smart-shopper

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core browsing, extraction, and local caching are broadly aligned with product research, but the skill increases trust exposure by instructing transitive skill installation and processing untrusted web content with write/exec capabilities. No clear credential theft or exfiltration endpoint is present, so this is not malicious, but it carries medium risk.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/axot%2Fagent-skills%2Fsmart-shopper%2F@a51a9711389061120b1a0b7dd83e83bf6ab373c3