api-test-generator

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose is coherent with its described workflow and references a legitimate testing pattern (DataStructure-driven test generation, OpenAPI validation). However, there are notable security concerns: hard-coded credentials in test fixtures, TLS verification disabled in requests, and potential exposure of tokens/logs. These issues render the skill as SUSPICIOUS rather than BENIGN. They warrant remediation before production use, such as using environment-provided test credentials, avoiding verify=False, and ensuring credentials/tokens are redacted in logs and version control.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:55 AM
Package URL
pkg:socket/skills-sh/mikopbx%2FCore%2Fapi-test-generator%2F@c1a208aedb378407cacce81ddd6a759fd321a1c1