ops-integrate

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core function is coherent, but it persistently stores raw credentials and then sends them to arbitrary discovered or user-supplied API endpoints without strong endpoint verification. No malicious installer or covert exfiltration is evident, yet the combination of credential handling, shared registry exposure, and untrusted discovery makes the skill medium risk.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-integrate%2F@5d416741f89bc3f2a335a19befb3813cd1ab7cbd