ss-cli-rotate-and-sync
Warn
Audited by Socket on Mar 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose is coherent for secret rotation, env sync, and service restart, but the core ss-cli dependency is unverifiable and receives a Secret Server token plus secret values. That combination makes the skill high risk from a supply-chain and credential-forwarding perspective, even though the stated workflow itself is plausible.
Confidence: 89%Severity: 86%
Audit Metadata