newman

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is an instructional Skill/README describing how to use the Newman CLI for running Postman collections. There is no embedded malicious code or obfuscated payload. The primary security concerns are operational: advice that can lead to credential exposure (passing secrets on the CLI), recommending disabling SSL verification, and installing additional npm packages without pinned versions. These are supply-chain and misuse risks rather than evidence of malware. Users should avoid placing secrets on command lines, avoid --insecure in production, pin package versions, and prefer CI secret stores and least-privilege reporters to reduce risk.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fnewman%2F@e017f2320ce999a4ce16c8f486bf3247d2868f79