ops-ecom

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Shopify/ShipBob API usage matches the stated e-commerce ops purpose, but the setup flow is far too invasive: it hunts for credentials across local files, password managers, keychain, browser history, and third-party secret stores before asking the user. Data flows mostly target official APIs, so this is not confirmed malware, but the credential-discovery behavior, broad permissions, and automated app-creation steps make the skill high risk and disproportionate to its stated purpose.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-ecom%2F@d4c37ffc1dcc482c59536ba95900abbed8425aff