juicebox-install-auth
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated purpose is coherent with installing an SDK and setting an API key, and there is no obvious exfiltration path beyond normal API use. However, trust in the actual SDK packages is not well verified: the npm/PyPI names and docs references appear inconsistent or unavailable, so the skill asks users to forward credentials into dependencies whose official provenance is unclear.
Confidence: 82%Severity: 56%
Audit Metadata