salary-market-scanner

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated salary-scanning purpose, and the TinyFish install/auth flow appears to use official vendor-documented paths. The main risk is that all browsing, prompts, and authenticated actions are delegated to a third-party CLI/service, creating medium data exposure and prompt-injection risk even though the credential and site access scope is mostly proportionate.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:56 PM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fsalary-market-scanner%2F@6abef7ac1d82681bb9d85ffff8cf968048117abc