coderabbit-install-auth

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it installs a CodeRabbit SDK and configures API key-based authentication using standard, officially distributed packages. Data flows involve credential input, local storage via env/.env, and authenticated API calls to CodeRabbit services. While generally benign, there is a mild risk related to credential exposure via environment files or logs; recommend best practices (local secret management, gitignore, minimal key permissions, and rotating keys). No evident credential forwarding to third-party binaries or covert data exfiltration patterns were observed.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcoderabbit-install-auth%2F@822a8776019dee3ece685d12ef33257147f21ead