marketplace-sdk-reference

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is a benign documentation/reference guide, and its network flow is limited to official Sitecore docs. However, the package names are internally inconsistent with Sitecore's official SDK distribution, creating a meaningful supply-chain/provenance concern. No malware-like behavior, credential harvesting, binary install, or exfiltration is present.

Confidence: 92%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fsitecore-skills%2Fmarketplace-sdk-reference%2F@09015498f951fbeb45d24ccc854aa51567e8824f