bknd-client-setup

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This Skill documentation and example code are consistent with a legitimate frontend SDK setup. There are no signs of obfuscated or malicious behavior. The main security concerns are operational: encouraging localStorage for token persistence and showing hard-coded secrets in examples (which are bad practices if copied to production), and potential verbose logging that could leak sensitive data. Recommend documenting XSS/CSRF mitigations, discouraging secrets in examples, and encouraging secure token storage practices.

Confidence: 85%Severity: 28%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:29 AM
Package URL
pkg:socket/skills-sh/cameronapak%2Fbknd-skills%2Fbknd-client-setup%2F@9d587b7e6d66d9a94916b947725bc6b95688b083