sop-product-launch

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. As a planning SOP, the skill is broader than necessary and blurs into operational execution with real-world consequences: deployment, app-store submission, marketing sends, paid ads, social posting, and PR outreach. The only explicit external component is a third-party MCP server (ruv-swarm); evidence suggests it is a real package/repo, but it is not same-org official to the skill host, and the skill gives no trust, install, or approval constraints. No direct credential theft, exfiltration endpoint, or malicious payload is shown, so this is not confirmed malware. Risk comes from disproportionate scope, autonomous action potential, and external tool trust.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fsop-product-launch%2F@023dca321a1a08f5a53fe5ab15e34a33bb8bee14