api-contract-testing

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill bundle is a benign API contract-testing toolkit: documentation, test examples, and scripts for validating OpenAPI specs, generating Postman collections, and running Pact-based consumer/provider tests. I found no signs of malicious code, obfuscated payloads, credential exfiltration, or download-and-execute supply-chain patterns in the provided content. The main security considerations are operational: ensure tests and state handlers run against isolated test databases and avoid using proxying to real production endpoints unintentionally. Follow standard supply-chain hygiene when installing third-party CLIs (install from official registries, pin versions, review package reputations).

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/pfangueiro%2Fclaude-code-agents%2Fapi-contract-testing%2F@4674d2806cc3f84110cb495dc495271dfc1d5b14