appdeploy

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The AppDeploy skill appears coherent and consistent with its stated purpose of deploying web applications via an AppDeploy JSON-RPC API. The primary security considerations are operational: storing a long-lived API key in a local plaintext file (.appdeploy) and transmitting user files to an external service. There are no supply-chain download-and-execute patterns, no evidence of credential exfiltration to unexpected third parties, and no obfuscated or hidden behavior. Overall this skill is low risk from the provided content, though users should treat the api_key as sensitive and ensure .appdeploy is excluded from source control and protected.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:32 PM
Package URL
pkg:socket/skills-sh/AppDeploy-AI%2Fskills%2Fappdeploy%2F@b9ecfa37dd966ecb2ae2bf549563169d0a6ebf24