swapper-integration

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Swapper Integration Skill fragment is a coherent, well-scoped scaffold intended to guide developers through researching, implementing, testing, and documenting swapper integrations. It emphasizes strong typing, monadic error handling, and careful API interaction patterns. The primary supply-chain risks arise from external documentation/SDK sourcing and secret management (API keys in environment variables). No executable payloads or credential exfiltration patterns are present in the fragment itself. The template is largely benign, but care must be taken to vet external sources, enforce secret-handling best practices, and ensure domain allowlists and verifiable endpoints in any real deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/shapeshift%2Fweb%2Fswapper-integration%2F@d1c0067f490211519f289aba1b61d89d468edf41