pg-boss

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The PG Boss skill is coherently aligned with its stated purpose of implementing reliable PostgreSQL-based job queues in Node.js/TypeScript. It demonstrates standard, legitimate usage patterns (initializing PgBoss, creating queues, scheduling, sending jobs, and workers) and relies on typical, trusted sources (npm registry, PostgreSQL). Data flows are contained to the application and database, with no evident credential harvesting, data exfiltration, or supply-chain risks beyond standard database credentials. Overall risk is low to moderate due to usual database exposure considerations; no malicious behavior or unsafe external downloads are evident.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:03 PM
Package URL
pkg:socket/skills-sh/blink-new%2Fclaude%2Fpg-boss%2F@f7438860955443a06019310b7167169c4bbc631f