guidewire-hello-world

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill demonstrates coherent purpose-capability alignment with its stated goal of testing connectivity and performing basic Guidewire API interactions. The footprint is proportional: no unverified binaries, no broad file access, and API-centric data flows to legitimate endpoints with token-based authentication. While credentials are handled via environment variables (which is common for integrations), this warrants standard security controls (env isolation, least-privilege tokens, and careful logging). The security risk is low to moderate (roughly 0.2–0.3), with no clear malicious behavior detected, but with customary credential-handling considerations recommended for production use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 12:20 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fguidewire-hello-world%2F@3b4483a6948556653d3e34e058eb30d4f7d83134