overvy

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Overvy board operations are coherent with the stated purpose and use direct API calls, but the skill also authorizes high-impact autonomous development actions (git push and PR creation) and allows bearer-token redirection through an overridable API URL. This is not confirmed malware, but it is a medium/high-risk skill because its action scope exceeds simple board management and can publish changes externally.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/martinhjartmyr%2Fskills%2Fovervy%2F@68978dfbdd954572f907a1d459aa6d0ff36ba02c