secrets-hygiene

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches a secrets-audit skill, and no external installer, third-party binary, or off-platform data flow is present. However, the capability footprint is broad: it instructs the agent to inventory secrets from env vars, config files, and keychain entries across installed skills, which is sensitive access disproportionate to many normal skills. Because the skill handles high-value credential material on a scheduled basis and the exact reporting/output boundary is not tightly constrained, it carries medium security risk despite no clear exfiltration behavior.

Confidence: 92%Severity: 52%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:56 AM
Package URL
pkg:socket/skills-sh/ArchieIndian%2Fopenclaw-superpowers%2Fsecrets-hygiene%2F@502e2f24f60915a16c64e18ef3d14a451079d246