salary-market-scanner
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly aligned with its stated salary-scanning purpose, and the TinyFish install/auth flow appears to use official vendor-documented paths. The main risk is that all browsing, prompts, and authenticated actions are delegated to a third-party CLI/service, creating medium data exposure and prompt-injection risk even though the credential and site access scope is mostly proportionate.
Confidence: 85%Severity: 54%
Audit Metadata