explore-recipes

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core browsing purpose aligns with the described MCP usage and ShipSwift endpoint, and the API key request is proportionate. The main concern is transitive skill installation via an unpinned `npx skills add` path, which introduces supply-chain and inherited-permission risk even though same-org evidence suggests the target skill is likely legitimate.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/signerlabs%2Fshipswift-skills%2Fexplore-recipes%2F@4f8aee7caddea45ba54a0475426250d98b2cab52