pachca-users

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a coherent and purpose-appropriate tool for Pachca user and tag management via official API endpoints. The footprint (token-based HTTP requests to trusted endpoints, standard CRUD operations, and onboarding/offboarding workflows) is proportionate to the stated purpose. There are no evident download/install chains, unverifiable binaries, or credential-forwarding to third-party tools. Some elevated risk exists around handling sensitive employee data (PII) and token leakage via logs or shell history; these are operational concerns rather than design flaws. Overall, classification: BENIGN with attention to secure handling of tokens and data at rest/in logs.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:43 PM
Package URL
pkg:socket/skills-sh/pachca%2Fopenapi%2Fpachca-users%2F@6893613fbfd463f6e3cf39a3e65ed5d86dda8db2