Poetry Packaging
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This skill is an instructional/tutorial document for Poetry packaging. The capabilities, installation sources (official Poetry & PyPI endpoints), and data flows are consistent with its stated purpose. No malicious behavior, backdoors, or credential-harvesting patterns were found. Minor caution: the curl | python install pattern and the use of CI secrets are legitimate but require users to trust the installer URL and to protect tokens properly.
Confidence: 88%Severity: 20%
Audit Metadata