get-qodo-rules

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is principally a legitimate repository-rule loader that fetches rules from a known platform using a local API key and environment configuration. Its data flows are coherent with the described purpose: locally stored credentials feed a remote API to retrieve rules, which are then formatted and applied to code tasks. Security posture is moderate: credential handling exists and must be protected from logging or inadvertent exposure, and network calls should be made with proper TLS and scope-conscious endpoints. No unverifiable binaries or credential-forwarding to third-party tools are indicated. Overall, the skill appears BENIGN with notable but manageable security considerations (credential exposure risk and network security).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fget-qodo-rules%2F@a69caaab10238b22f692898c919399477d4edd3c