deco-apps-vtex-review

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns well with its stated purpose: auditing and fixing VTEX integration concerns in a Deco-backed apps-start context. The footprint is proportionate and focused on legitimate VTEX IO/API interactions (cookie management, auth headers, required order form sections, sc handling, and hook parity). No evidence of unverifiable binaries, credential harvesting, or external data exfiltration is present. Security posture appears benign with a low-to-moderate risk profile, largely due to standard VTEX integration patterns and HttpOnly cookie handling. Ensure ongoing adherence to the explicit audit checks (no hardcoded cookies, proper sc handling, and removal of debug logs) to maintain a benign risk posture.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/decocms%2Fdeco-start%2Fdeco-apps-vtex-review%2F@d7fe04fa50b8e573fea7d4952396c587ff1380cb