micepad

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s capabilities are broadly aligned with its stated event-management purpose, and the Micepad-branded endpoint is consistent with that purpose. The main issue is trust: it hinges on an authenticated external CLI with no verifiable install/provenance details in the skill, and that CLI can perform high-impact operational actions and handle sensitive event data. This is best classified as suspicious/high-risk rather than confirmed malicious.

Confidence: 79%Severity: 84%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:48 AM
Package URL
pkg:socket/skills-sh/micepadteam%2Fskills%2Fmicepad%2F@df27ee8587806a39ec9577b417453f290399210f