cook-the-blog

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core blog-writing purpose is plausible, but the skill is overpowered: it researches untrusted web content, executes external scripts/builds, uploads files, pushes directly to a repository, and sends mandatory email summaries. The data flows are not clearly malicious, yet the scope and autonomy are disproportionate for a writing skill and create meaningful supply-chain, prompt-injection, and credential-exposure risk.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Apr 19, 2026, 08:36 AM
Package URL
pkg:socket/skills-sh/Varnan-Tech%2Fopendirectory%2Fcook-the-blog%2F@0584d70719f1511786d2e1849aa2745e21a0f141