bring-shopping

Fail

Audited by Socket on Mar 24, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s shopping-list actions match its stated purpose, but it depends on an unofficial third-party library and passes full account email/password credentials into that code. The install path is ordinary npm, not a raw malware-style downloader, yet the credential model and unofficial integration make the trust boundary disproportionate versus an official API-based skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:25 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fbring-shopping%2F@cb4393e12a7e74087023e85c313d1a6448b2abee