create-boss

Warn

Audited by Socket on Apr 8, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall purpose is coherent, but the footprint is broader than necessary and underspecified in key places. Sensitive workplace data collection is central to the skill, yet auto-collector/MCP/browser tooling and Bash-enabled file operations create medium-to-high security risk without clear endpoint, auth, or safety constraints.

Confidence: 83%Severity: 69%
AnomalyLOW
tools/feishu_mcp_client.py

No clear malicious payload is present within this Python snippet itself. The primary concerns are (1) supply-chain/execution risk from running `npx -y feishu-mcp` at runtime (dynamic resolution/installation/execution) and (2) plaintext storage of high-value Feishu credentials in a predictable file under the user’s home directory, plus (3) passing those secrets to a child process via environment variables and (4) writing fetched content to an arbitrary user-specified output path.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Apr 8, 2026, 05:50 AM
Package URL
pkg:socket/skills-sh/nicepkg%2Fboss-skill%2Fcreate-boss%2F@5d085bbc7b599f71f02d4bf9ff4979c3b017c5cb