domain-researcher

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core purpose is coherent, but the install/execution path is weaker than it should be because it relies on an unpinned external `npx` package with unclear provenance, plus all domain research data flows through a single third-party API. This looks more like a risky vendor-integrated research skill than overtly malicious content.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 01:55 PM
Package URL
pkg:socket/skills-sh/madarco%2Fchatdomain-researcher%2Fdomain-researcher%2F@5c4180c7a25024cbd84b9cd56dd95a961751d045