tapd-bug-analyzer

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, but it introduces moderate security risk through credential forwarding to a not-clearly-first-party MCP server, dependence on another unreviewed local skill, and execution paths influenced by untrusted bug content. No clear malicious intent or overt exfiltration is shown, but the trust and data-flow boundaries are broader than ideal for a bug analysis helper.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 19, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/abcfed%2Fclaude-marketplace%2Ftapd-bug-analyzer%2F@da93c7944088877c5e8ef09def8de016965decac