competitor-teardown
Audited by Socket on Feb 18, 2026
1 alert found:
Malware[Skill Scanner] Pipe-to-shell or eval pattern detected BENIGN: The improved report describes a legitimate competitive teardown workflow with public data sources and CLI automation. It produces standard market intelligence deliverables and maintains a reasonable security posture, aside from the general bootstrap risk associated with external tooling. Recommend validating data sources and monitoring provenance of any bootstrap scripts in production use. LLM verification: The SKILL.md is functionally coherent for a competitor teardown skill and does not contain explicit malicious code in the provided text. The primary security concern is the recommended pipe-to-shell installer (curl | sh) and the implicit routing of scraped content and credentials through a third-party hosted platform (inference.sh/infsh) without documented integrity checks or privacy/retention policies. This creates a supply-chain and data-exfiltration risk if the installer or backend is comprom