update-os-packages

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its maintenance purpose, but it depends on an authenticated custom tool feed in a personal GitHub Packages namespace and instructs storing a token in clear text. Data flows are largely coherent and there is no strong evidence of credential harvesting or unrelated exfiltration, so this looks more like a medium-risk trust and credential-handling issue than malware.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/dotnet%2Fcore%2Fupdate-os-packages%2F@ac25d264805d0379634f3922bc40acc9d799b123