spark

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but its implementation relies on unverifiable bundled binaries, and one of them receives an API key despite not matching Tavily’s documented official integration path. The main concern is install/execution trust and credential forwarding to opaque local code, not overt malicious behavior.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:32 AM
Package URL
pkg:socket/skills-sh/quinteroac%2Fspark-marketing-guru%2Fspark%2F@c7e4e03457605735a7833da1b5f79362055b1878