api-helper

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This artifact contains explicit, unsafe instructions that will cause disclosure of sensitive credentials (OPENAI_API_KEY, SLACK_TOKEN, ANTHROPIC_API_KEY and full Authorization headers) if an agent follows them. While there is no executable malware code in the fragment, the content is a high-risk credential-exfiltration pattern and should be treated as dangerous: remove or change the instructions to enforce masking, confirmation, or secure local debugging procedures before use in any environment with real secrets.

Confidence: 75%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/MohibShaikh%2Fclawvet%2Fapi-helper%2F@0d022b9d06478b14c7b01c6e0674969597d1e173