NYC

dspy

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL.md document appears to be a legitimate, descriptive skill/integration guide for the dspy framework. It asks for expected permissions (LM API keys, local filesystem access for saving models/databases, optional local LM endpoints) and routes data in the expected way to configured LM providers. There are no signs of obfuscated or intentionally malicious code, credential-harvesting redirection domains, hidden exfiltration, or remote payload instructions in the supplied content. The main risks are operational: accidental logging/tracing of sensitive prompts or API keys and the usual risk of sending sensitive data to third-party LMs. No evidence supports classification as malicious; treat this as generally benign but exercise standard caution with API keys and tracing.

Confidence: 70%Severity: 25%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:49 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Fdspy%2F@cac77bfe551696fb6ed72a60068fcd3a70eea769