credentials

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior mostly matches its stated purpose, and data flows go to official APIs rather than third-party endpoints, so it does not look malicious. However, it is high-sensitivity by design: it reads centralized local credential files, extracts many unrelated secrets, and writes them into project .env files, which is broader and riskier than a narrowly scoped setup skill.

Confidence: 90%Severity: 54%
Audit Metadata
Analyzed At
Apr 9, 2026, 07:28 PM
Package URL
pkg:socket/skills-sh/alinaqi%2Fclaude-bootstrap%2Fcredentials%2F@2b9edcb7772ce9613e4c4b4eb3f9739e2219b81c