saccoai-client-portal

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core portal-generation behavior is coherent with the stated purpose, especially in static mode, but deployed mode materially expands scope: it handles raw secrets, deploys infrastructure, stores client feedback in Upstash, sends email through Resend, and triggers downstream cleanup actions. These behaviors are not inherently malicious and mostly use official services, but the credential handling and third-party data flows make the enterprise path medium risk.

Confidence: 86%Severity: 59%
Audit Metadata
Analyzed At
Mar 27, 2026, 09:18 AM
Package URL
pkg:socket/skills-sh/saccoai%2Fagent-skills%2Fsaccoai-client-portal%2F@2aa62f1ba9dbfc241ec036b3b132616aa7ae2ab8