outlit
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill descriptor is internally coherent with its stated purpose as a unified CLI for customer data analytics. It uses standard, publicly distributed installation channels (npm and Homebrew) and a conventional API-key-based authentication flow to a centralized MCP endpoint. The data flows (API key -> MCP -> JSON output) are appropriate for this kind of tool but require proper credential hygiene and access controls to avoid credential leakage or unintended data exposure in logs or CI environments. Overall posture is BENIGN with notable security considerations around credential management and data exposure in shared contexts.
Confidence: 75%Severity: 75%
Audit Metadata