keypo-signer

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of hardware-bound key management and secure secret injection into subprocesses. Its use of Secure Enclave, vault-based secret storage, and environment-injection semantics align with a tightly controlled security model. While there are legitimate security considerations around how decrypted secrets are exposed to child processes and potential automation pitfalls, there is no evident malicious data flow or external credential harvesting pattern. Overall, the tool appears BENIGN with MEDIUM risk due to sensitive data handling in automated workflows and the potential for misconfiguration in unattended use; no unverifiable binaries or obvious exfiltration channels are evident.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/keypo-us%2Fkeypo-cli%2Fkeypo-signer%2F@0c787c28f09101440f4eea4ef84d313418d2a603