ave-data-wss

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities are mostly aligned with its stated purpose, and its credential scope is proportionate. The main concern is data-flow integrity: the authenticated runtime endpoint wss://wss.ave-api.xyz is not clearly documented as an official Ave-owned host in public first-party materials, while docs links point to cloud.ave.ai/doc.ave.ai. Combined with unpinned local dependencies and Docker credential forwarding, this makes the skill medium risk rather than benign, though there is not enough evidence to call it malicious.

Confidence: 78%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/avecloud%2Fave-cloud-skill%2Fave-data-wss%2F@9df0ffd0dc911ad6672da21637a062a9323bcac6