skill-upload

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign overall with caution. The skill-uploader workflow is coherent with its stated purpose (secure upload, structure audit, classification, and MCP submission). Key security considerations revolve around secure handling of the UPLOAD_SECRET and GitHub tokens, ensuring TLS and server-side validation, and avoiding embedding secrets in accessible files. The most notable risks are potential misconfiguration of secret management in MCP config exemplars and reliance on server-side validation for password matching; these should be mitigated with explicit guidance on secret hygiene and secure config practices.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/rj-yingjunjie%2Fskill-hub%2Fskill-upload%2F@ee7a67a5ce6393860f70a533bc6da7b9a0838ab8