openrouter-typescript-sdk

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill footprint is coherent with a legitimate TypeScript SDK designed to interface with OpenRouter via API keys or OAuth PKCE, offering a rich feature set for tool-based interactions and streaming. There are no evident download-execute supply-chain patterns, no unverifiable binaries, and credential handling is aligned with standard SDK usage (environment variables, per-request API keys). The primary risks relate to typical credential exposure in client/server apps (environment leaks, embedding keys in front-end code) and the potential for misconfiguration by integrators; otherwise, the data flows and capabilities appear proportionate to the stated purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:03 AM
Package URL
pkg:socket/skills-sh/OpenRouterTeam%2Fskills%2Fopenrouter-typescript-sdk%2F@3bb86f0162597d1fefa0ef98c391b211f47dfda9