dibbla

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with a platform CLI, but its footprint is high-risk: custom-domain pipe-to-shell installation, remote YAML execution equivalent to `curl|bash`, token persistence into `.env`, and real deployment/secret/database actions. I do not see clear evidence of outright credential theft or covert exfiltration, but the execution and supply-chain trust model are risky enough to classify as suspicious rather than benign.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 7, 2026, 07:55 AM
Package URL
pkg:socket/skills-sh/dibbla-agents%2Fskills%2Fdibbla%2F@05958dba8b02b11fb80ba8fe84ad6c32f1f906e5