launchpad-webembed

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent and data flows target official Pega services, so it does not look malicious. However, it includes a browser-side Client Credentials pattern that exposes clientSecret through NEXT_PUBLIC variables and passes it to a remotely loaded web component, creating disproportionate credential-forwarding risk; the remote script load is same-vendor but unpinned.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 7, 2026, 01:03 PM
Package URL
pkg:socket/skills-sh/pegasystems%2Fpega-launchpad-agent-skills%2Flaunchpad-webembed%2F@b1e2647de9d5b488d4c89720cc48e3a5fe1cc433