javascript-sdk

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the code fragment represents a coherent and proportionate SDK intended to interface with inference.sh services. There are no evident malicious behaviors, credential harvesting patterns, or unnecessary data exfiltration signals in the provided content. The primary risks revolve around proper secure handling of API keys in frontend contexts and ensuring proxy configurations do not inadvertently leak secrets. Treat as BENIGN with standard supply-chain considerations; monitor for secure deployment practices in real usage.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Mar 2, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/DuveSalo%2Fapp%2Fjavascript-sdk%2F@c15d88cbea73fe9111354bb92972b0fd4bacb003