dev-scan

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the research purpose is legitimate, and most API/data flows fit that purpose, but the skill’s footprint is not fully proportionate because it relies on an unverifiable external `chromux` binary and combines untrusted-content ingestion with bash/file capabilities. Product Hunt token use is expected, but the opaque browser tool makes install trust the dominant risk.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fdev-scan%2F@53bcb02929c46c67029a11b772bd48571bf21d9e