connect

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent for a deployment workflow, and exe.dev SSH usage appears consistent with official docs, but the footprint is still risky. It combines infrastructure access, npm-based local execution, remote repo deployment, and direct handling of a Clerk secret key passed via CLI. The main concern is disproportionate secret exposure and moderate supply-chain uncertainty from the unseen deploy script and remote branch clone, rather than clear malicious intent.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/popmechanic%2Fvibes-cli%2Fconnect%2F@0eda8e137d34711ccbf9e8314b488bb97a85ac19