competitor-teardown

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the research purpose is mostly consistent, but the trust chain is weak because the skill asks the agent to install another remote skill/CLI through `npx skills add`, uses ambiguous publisher naming (`belt-sh` vs `inference-sh`), and routes research data plus login state through third-party Belt services. The main risks are transitive install trust, third-party credential forwarding, and prompt-injection exposure from processing untrusted web content with execution capability.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:03 AM
Package URL
pkg:socket/skills-sh/whytryharder%2Fskills%2Fcompetitor-teardown%2F@ef60db86bf031f83735a3fa5ca3bac8918f0241c351e06a549ff59871b3d5ecc
Security Audit — socket — competitor-teardown