ecommerce-competitor-analysis

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose is coherent and the referenced repo appears legitimately associated with Nexscope, so there is no strong evidence of malware. The main concern is trust expansion: it requires installing a third-party skill through the Skills CLI with global scope, and that CLI supports broad external sources and collects telemetry by default. Overall this is best classified as SUSPICIOUS due to transitive installation and supply-chain exposure, not confirmed malicious behavior.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Mar 24, 2026, 07:32 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2FeCommerce-Skills%2Fecommerce-competitor-analysis%2F@7b9aaf3eb82e10ae1b66755f2c06aa67d8ac3f39