credentials

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent local credential store with strong at-rest encryption and explicit metadata handling. The primary risk is exposure of sensitive values through stdout (get subcommand) and potential master-password leakage via CLI flags or environment variables. Overall, the footprint is proportionate to a local secret manager but warrants mitigations around stdout privacy, CLI-history exposure, and secure password entry (prefer interactive prompts or secure prompts via the runtime). The design is MITRE-leaning toward benign with moderate security risks due to data-in-use exposure vectors.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:13 PM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Fcredentials%2F@8a534881222743ab83cb5be93aedd2a510c4019d