finalrun-generate-test

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned for generating FinalRun test artifacts, and its file access is mostly proportionate. However, it requires and executes an unverified `finalrun` CLI and explicitly relies on that binary to resolve secret-bearing environment bindings, creating a significant supply-chain and credential-forwarding risk despite no direct exfiltration endpoint in the skill itself. Overall classification: SUSPICIOUS.

Confidence: 79%Severity: 82%
Audit Metadata
Analyzed At
Apr 16, 2026, 10:18 AM
Package URL
pkg:socket/skills-sh/final-run%2Ffinalrun-agent%2Ffinalrun-generate-test%2F@46a0fa5fd0fb665e94d237f0e1c1f78d9acd1fc2