operon-services

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s behavior is mostly aligned with its stated purpose of service inspection and local forwarding, and it avoids credential collection or third-party data routing. However, it depends on an `operon` executable whose official provenance could not be verified from the skill or public evidence, so the required binary is effectively unverifiable; combined with its ability to open local/public listeners, this makes the overall security risk high despite limited evidence of malicious intent.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
May 3, 2026, 04:09 AM
Package URL
pkg:socket/skills-sh/denghongcai%2FOperon%2Foperon-services%2F@e6cddaeb82629283f6f38cab58802240912ecdfc