ops-yolo

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH RISK. The skill’s stated purpose matches business analysis and operations, but its actual footprint is excessively broad: it collects extensive sensitive context, resolves multiple high-value credentials, consumes untrusted external content, and enables autonomous real-world actions. Most importantly, it invokes opaque local ops-* binaries with no verifiable provenance while likely exposing secrets to them, which triggers a high-risk supply-chain and credential-forwarding concern.

Confidence: 90%Severity: 92%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:51 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-yolo%2F@db5f9682261a33a9c8226286e54de2146d6cf07a