competitor-teardown

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected BENIGN: The improved report describes a legitimate competitive teardown workflow with public data sources and CLI automation. It produces standard market intelligence deliverables and maintains a reasonable security posture, aside from the general bootstrap risk associated with external tooling. Recommend validating data sources and monitoring provenance of any bootstrap scripts in production use. LLM verification: The SKILL.md is functionally coherent for a competitor teardown skill and does not contain explicit malicious code in the provided text. The primary security concern is the recommended pipe-to-shell installer (curl | sh) and the implicit routing of scraped content and credentials through a third-party hosted platform (inference.sh/infsh) without documented integrity checks or privacy/retention policies. This creates a supply-chain and data-exfiltration risk if the installer or backend is comprom

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fcompetitor-teardown%2F@bdcf5f4d92b71e991955b525eb421633a412096c