moai-platform-deployment
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: overall the skill is mostly coherent as a deployment guide, with official-looking platform coverage and proportionate capabilities. The main issue is the Vercel CI example routing sensitive deployment credentials through an unrelated third-party GitHub Action, which weakens data-flow integrity and raises medium risk; otherwise the skill does not show clear malicious behavior.
Confidence: 90%Severity: 52%
Audit Metadata