competitive-analysis

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose: it asks for internal product context, uses web browsing to capture competitor screenshots, and writes structured competitive analyses and assets to the workspace. There are no direct malicious indicators (no code-execution downloads, no hardcoded secrets, no known exfiltration endpoints). Primary security concerns are operational: granting automated browsing and write access to workspace files can expose confidential internal material or login-gated UIs, and using third-party image-generation APIs may leak initiative details. Treat the skill as generally safe for its purpose but apply platform safeguards: limit subagent reach, require per-URL approvals, and avoid sending sensitive content to external image-generation services.

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:33 PM
Package URL
pkg:socket/skills-sh/tylersahagun%2Fpm-workspace%2Fcompetitive-analysis%2F@ba77b47f4e02cc095db569e109263d1fe84541d9