publish-blog

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall workflow is largely consistent with a blog-publishing skill, and the explicit approval gate helps. The main concerns are install/execution trust and credential handling: the skill depends on unspecified local executables and MCP-mediated integrations whose provenance and token routing are not defined in the skill. No clear credential harvesting or unrelated exfiltration is shown, so this is better classified as a medium-risk, trust-gap-heavy skill rather than malware.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Apr 1, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fpublish-blog%2F@55d393c038ca5616ed12103e509a301451621edb