ghost-paper

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core function is plausible, but it depends on executing an unpinned npm package whose provenance was not verified in the supplied evidence, and it instructs the agent to trust live guidance emitted by that package. No direct credential theft or exfiltration is shown, but runtime package execution and global-install fallback create meaningful supply-chain risk.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 13, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/timescale%2Fmarketing-skills%2Fghost-paper%2F@adee700f139087627c81f2033924d9102d76247c