geo-update

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as an updater, but it trusts a personal GitHub repo as the live source of code and dependencies, then overwrites local agent/skill files and runs pip install from that clone. No clear credential theft or exfiltration appears, so this is not malware, but it carries medium supply-chain risk.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/zubair-trabzada%2Fgeo-seo-claude%2Fgeo-update%2F@dfcc000390f912fa13f2654a38245ee9550565f6