andromeda-messages

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is functionally coherent with its stated purpose (CRUD and lock management for an Andromeda page). The primary security concern is the inclusion of a hardcoded bearer token in the documentation and the use of a single shared token for all operations, which is an overprivileged credential-exposure risk. There are no download/execution supply-chain indicators or obfuscated code. The destructive operations (DELETE, lock/unlock) increase the impact of any leaked credential and make per-action authorization/auditing important. Overall risk is moderate: safe if the token is placeholder and not valid, but potentially high if the token is real and the skill is reused without replacing or rotating credentials.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:54 PM
Package URL
pkg:socket/skills-sh/Michailbul%2Flaniameda-skills%2Fandromeda-messages%2F@e96033aecd2b58671fe757c9b5f3d561a9d8ff54