returns-refund-policy

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose and capabilities mostly align: configuring return policies through known ecommerce returns tools or local policy code is coherent. However, the ReturnGO installation/source instructions are internally inconsistent with verified official domains, and the documented ReturnGO integration requires forwarding WooCommerce API credentials to the vendor, which materially increases risk. This is not confirmed malware, but it is a medium-to-high risk business-operations skill due to third-party trust expansion and credential-sharing requirements.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 16, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/finsilabs%2Fawesome-ecommerce-skills%2Freturns-refund-policy%2F@b805e1ee82b37561c0f48efb1c4e9e0516f731e6