moai-platform-deployment

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: overall the skill is mostly coherent as a deployment guide, with official-looking platform coverage and proportionate capabilities. The main issue is the Vercel CI example routing sensitive deployment credentials through an unrelated third-party GitHub Action, which weakens data-flow integrity and raises medium risk; otherwise the skill does not show clear malicious behavior.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:19 AM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-adk%2Fmoai-platform-deployment%2F@a513d2bb17e378acf588e99bcdf5e0af6339dda8