blog-writer

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core behavior is coherent for a blog-generation skill and there is no direct credential harvesting or exfiltration. Risk comes from two trust boundaries: repo-defined `npm run build` execution and the undocumented third-party `frontend-design` plugin/skill, whose provenance is unclear. Overall this is not malicious on the evidence shown, but it is not fully benign because it expands trust to external or unverified execution surfaces.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/peterbamuhigire%2Fbusiness-plan-skills%2Fblog-writer%2F@7feea24f748ff3599f5fcf9860eeedbf5221bf4a