amazon-buy-box

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose and capability scope are benign and proportionate, with no credential requests or exfiltration behavior in the provided content. The main risks are supply-chain and trust-chain related: installation depends on an unpinned `npx` CLI and a transitive skill install, and the documented repo does not match the repo where this skill actually appears. That inconsistency is enough to treat it as suspicious rather than benign, but there is no evidence here of confirmed malicious behavior.

Confidence: 89%Severity: 52%
Audit Metadata
Analyzed At
Mar 24, 2026, 07:32 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2FAmazon-Skills%2Famazon-buy-box%2F@dfbda7ebb62afae8ee7fdc558abfc9000061c69b