panda-analytics

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's analytics purpose is coherent, but it reads a raw local API key and sends it to a fully configurable `api_url` without constraining the destination to a verifiable official Nosy Pandas endpoint. There is no malicious installer or overt exfiltration service, but the credential-forwarding and endpoint-integrity model create medium risk.

Confidence: 88%Severity: 66%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:58 PM
Package URL
pkg:socket/skills-sh/mrpaulscrivens%2Fnosy-pandas-skills%2Fpanda-analytics%2F@f749038e497bd6a23d5153d49069afd475e9cd0b