mocreo-api

Warn

Audited by Socket on Mar 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
mocreo-smart-system/SKILL.md

SUSPICIOUS: The skill is broadly coherent with a legitimate MOCREO device-management integration and appears to target official service APIs, not an obvious third-party interception domain. Main concerns are automatic dependency installation from an unseen requirements file, persistent storage of credentials/tokens/API keys in .env, and agent-enabled side-effecting actions including API key management and export-to-email. This is not confirmed malware, but it carries moderate security risk due to secrets handling and unverifiable local script behavior.

Confidence: 81%Severity: 54%
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches MOCREO device management, and official MOCREO domains exist, but the trust boundary is the unseen local login/setup scripts that collect account credentials and may make network calls. With no remote installer or obvious exfiltration endpoint shown, this is not confirmed malicious, but credential handling and shell-based execution create medium risk until the scripts and endpoints are reviewed.

Confidence: 78%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 02:55 AM
Package URL
pkg:socket/skills-sh/mocreo-iot%2Fskills%2Fmocreo-api%2F@89f53a9f2c848026cc016348b5cfa9f254ac125a