where-your-customer-lives

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior fits its stated purpose, but it mixes broad untrusted web ingestion with file-writing capability and routes some research through third-party services like HN Algolia instead of only official APIs. The optional GITHUB_TOKEN is proportionate, yet it is passed into unseen local code, so the overall risk is moderate rather than benign.

Confidence: 85%Severity: 53%
Audit Metadata
Analyzed At
May 2, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/Varnan-Tech%2Fopendirectory%2Fwhere-your-customer-lives%2F@83035a1ba3ee90703abc96a36a87ad4705d0e358
Security Audit — socket — where-your-customer-lives