pagerduty-oncall

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but it relies on a deprecated personal PagerDuty CLI and forwards a live PagerDuty API token into that third-party executable. Data flows are otherwise aligned with PagerDuty investigation and there is no explicit proxy/exfiltration behavior in the skill text, so this is better classified as high-risk vulnerable than confirmed malicious.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Mar 26, 2026, 11:33 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Fpagerduty-oncall%2F@11ca649b40393cf53f3681ee73e09032466c7819