ops-revenue

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core billing and revenue functions mostly match the stated purpose and use official AWS/Shopify endpoints, but the skill’s footprint is elevated by secret resolution through a third-party CLI and, more importantly, execution of an unverifiable local binary (`bin/ops-external`). That unverifiable executable is disproportionate to a simple reporting skill and forces a high security-risk classification, though the evidence does not confirm malware or explicit credential theft.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-revenue%2F@3645d0dd0184f0c57180002e2c8c67804473f3bb