shelf-life-check

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill relies on an unverified external CLI and mixes untrusted web research with record-changing commands. Main risk is supply-chain trust in `grocer-cli` plus indirect prompt-injection from web content, not clear malware or credential theft.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Mar 23, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/sieteunoseis%2Fgrocer-cli%2Fshelf-life-check%2F@fa9df709246d98145649e2d07b142bac30792dba