appdeploy

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: overall purpose and capabilities mostly align for a deployment skill, and data flows go to the claimed vendor domain rather than an obvious third-party interceptor. The main concerns are the uncorroborated manual API-key bootstrap, local storage of a long-lived credential, and consequential remote actions that publish code and can delete apps. This looks more like a legitimate but medium-risk deployment integration than malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 18, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fappdeploy%2F@9bf790d0430afba87df65a2afb52b946e6c06ee7