bytestash
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The ByteStash skill presents a coherent and appropriately scoped tool for snippet management with standard CLI-based interactions and API-backed data handling. Credential handling is constrained to a per-user API key in a local .env file and HTTP headers, and operations map directly to the feature set (CRUD, sharing, organization). There are no evident malicious data flows or unverified binaries. Some risks exist around share link exposure and local credential handling, but these are expected trade-offs for a snippet storage service. Overall verdict: BENIGN with MEDIUM security considerations due to potential data exposure via sharing and careful credential management required.
Confidence: 98%
Audit Metadata