magic-link-auth-companion
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly aligned with magic-link auth management, but it routes sensitive token operations to a custom, configurable external backend and includes a local revocation script whose provenance is not verifiable from the snippet. No clear malware or overt credential theft is present, but the external data path and operational scope make it a medium-risk skill.
Confidence: 82%Severity: 58%
Audit Metadata