recipe-to-cart

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's cart-writing behavior matches its stated purpose, and no clear credential theft or exfiltration is shown. The main concern is install/execution trust: it depends on a third-party CLI from npm without clear proof that the package is official or controlled by the same publisher, while also enabling real-world shopping actions the agent cannot verify afterward.

Confidence: 79%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/sieteunoseis%2Fgrocer-cli%2Frecipe-to-cart%2F@a0d2b53e211a54bdcd593f359b1a71f8f33ae8c5