commafeed-api

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The CommaFeed REST API skill demonstrates coherent purpose-capability alignment: it defines environment-based credentials and a comprehensive set of REST endpoints for managing feeds, categories, entries, user settings, and admin functions. It relies solely on standard HTTP(S) calls to a trusted host, without downloading executables or forwarding credentials to unknown third parties. The data flow is straightforward (local credentials -> target API) and proportionate to its stated task. Minor concerns include potential credential exposure via logs in real deployments and ensuring proper role checks for admin endpoints, but no fundamentally malicious or misaligned capabilities are evident. Overall, the skill footprint is Benign with MEDIUM-low securityRisk due to credential handling considerations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/biggora%2Fclaude-plugins-registry%2Fcommafeed-api%2F@767f0f562c675e0e977ad704faec36bf34807f5f