substracker

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign-to-moderate risk: the skill is purposefully scoped to manage SubsTracker resources via a CLI and legitimate notifier integrations. The main security considerations are secure handling of API credentials and notifier tokens, ensuring logs do not leak secrets, and validating that bun/runtime sources are trusted. The data flows are consistent with the stated purpose; there are no evident malicious data exfiltration patterns. Treat as suspicious only if notifier credentials or environment secrets are logged or transmitted insecurely.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 02:39 PM
Package URL
pkg:socket/skills-sh/ianchenx%2Fsubstracker-skills%2Fsubstracker%2F@c1a039f419d5a9d060e73f382b4cffe20abe1ccb