competitor-product-monitor

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but it unnecessarily depends on an external AI/web-agent CLI whose trust relationship is not established in the provided evidence. The biggest risks are third-party tool trust and indirect prompt injection from untrusted websites combined with shell access; this is not clearly malicious, but it is not low-risk.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Apr 19, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fcompetitor-product-monitor%2F@288546898039c9e1555cbe1366573c2e26e01bc9