benchmark-e2e

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior is coherent for a benchmark harness, but it executes local project code and documents unattended looping while failing to identify the exact plugin source being installed. No clear credential harvesting or external exfiltration is shown, so this is not malware, but it carries medium security risk from incomplete install provenance and broad local code execution.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:24 AM
Package URL
pkg:socket/skills-sh/vercel%2Fvercel-plugin%2Fbenchmark-e2e%2F@e6ba6fc14033d62e7279a5d0b350b4864f4e700f