synthetic-monitoring

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The module implements plausible synthetic monitoring and testing functionality and is consistent with its documented purpose. It does not contain obvious obfuscated or explicitly malicious code (no remote install-execute, no reverse shells, no encoded payloads). However, there are significant security and operational risks: hardcoded test credentials, plain HTTP (unencrypted/unauthenticated) posting of metrics and alerts, scheduled autonomous runs that create accounts and payments (side effects), and no safeguards/redaction for tokens. If deployed against production or misconfigured to attacker-controlled targets, this code could leak credentials or perform undesired actions. Recommend: remove hardcoded credentials, require HTTPS and authentication for telemetry/alert endpoints, ensure tests are run only in safe test environments, avoid side-effecting flows against production, and add redaction and configuration validation.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/aj-geddes%2Fuseful-ai-prompts%2Fsynthetic-monitoring%2F@fe066fa8b03cab3313007f6f69b64f62de788fde