ops-dash

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated dashboard purpose only partially matches the actual footprint. Reading local status and routing is expected, but the skill also enables broad shell execution, file writes via bash, outbound sharing, and downstream autonomous operational actions such as YOLO mode, messaging, deploy, and auto-merge. No confirmed malware or obvious credential theft is shown, but the scope is disproportionate for a dashboard and carries meaningful real-world action risk.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-dash%2F@5c5660fcddcab26b847dc2ccea3797872d76a215