superme

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its supermarket automation purpose and its network flows stay on official vendor domains, so this is not clearly malicious. However, it auto-installs an external CLI, exports auth cookies, stores tokens in plaintext /tmp files, and performs real account actions; that makes it a medium security risk despite generally coherent purpose alignment.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:23 PM
Package URL
pkg:socket/skills-sh/aloncarmel%2Fsupermeskill%2Fsuperme%2F@dd680a5121aa25472263da41a1dc579d28d09cba