mocreo-smart-system

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/v3_get_device_history_auto.py

This file appears to be a legitimate CLI wrapper that coordinates auth resolution and a single HTTPS API call to fetch device history and format timestamps. There is no direct evidence of malicious code in this module (no obfuscation, no shelling out, no persistence/backdoor behavior). The principal security concerns are accidental disclosure of sensitive auth metadata and telemetry because the script prints summarize_auth(auth_info) and the full history payload to stdout, and the use of allow_token_fallback which may broaden credential usage. I recommend auditing the referenced helper modules for token handling, ensuring printed auth summaries are redacted, and making the API endpoint configurable.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/mocreo-iot%2Fskills%2Fmocreo-smart-system%2F@49b1aade20151053c438ba1500d961299857167e