dev-pain-finder

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and browsing behavior are broadly coherent, but it routes public-web research through a third-party authenticated CLI/service and the install instruction mismatches TinyFish’s official documented package name. Main risks are supply-chain/install trust and indirect prompt injection from untrusted scraped content, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fdev-pain-finder%2F@a6837c2b66e4958d8fd70a18011f28694438facd