Poetry Packaging

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is an instructional/tutorial document for Poetry packaging. The capabilities, installation sources (official Poetry & PyPI endpoints), and data flows are consistent with its stated purpose. No malicious behavior, backdoors, or credential-harvesting patterns were found. Minor caution: the curl | python install pattern and the use of CI secrets are legitimate but require users to trust the installer URL and to protect tokens properly.

Confidence: 88%Severity: 20%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:41 PM
Package URL
pkg:socket/skills-sh/pluginagentmarketplace%2Fcustom-plugin-python%2Fpoetry-packaging%2F@e9eecdcf2b1d86b5f0096d0ca6124615d4e71591