competitor-teardown
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the research purpose is mostly consistent, but the trust chain is weak because the skill asks the agent to install another remote skill/CLI through `npx skills add`, uses ambiguous publisher naming (`belt-sh` vs `inference-sh`), and routes research data plus login state through third-party Belt services. The main risks are transitive install trust, third-party credential forwarding, and prompt-injection exposure from processing untrusted web content with execution capability.
Confidence: 85%Severity: 76%
Audit Metadata