dev-pain-finder
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose and browsing behavior are broadly coherent, but it routes public-web research through a third-party authenticated CLI/service and the install instruction mismatches TinyFish’s official documented package name. Main risks are supply-chain/install trust and indirect prompt injection from untrusted scraped content, not confirmed malware.
Confidence: 84%Severity: 58%
Audit Metadata