competitor-teardown

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected BENIGN: The skill fragment is a coherent, proportionate toolchain for competitive teardown and market research. It leverages publicly accessible data sources through a legitimate CLI workflow to produce deliverables. No credential collection, backdoors, or suspicious data exfiltration patterns are evident. LLM verification: The skill's capabilities match its stated purpose (competitive research, screenshots, plotting) but rely on a third-party CLI and remote apps in the inference.sh ecosystem. The use of curl | sh to install the CLI and the absence of any data-handling, credential, or retention disclosures are the primary risks: they create opportunities for credential exposure, data exfiltration, or arbitrary code execution depending on the installer's behavior and the backend services. I find no explicit maliciou

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 19, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fgtm-skills%2Fcompetitor-teardown%2F@80a57ee1fd519613ca6e089e483144750ced58dd