dot

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose (querying company data via Dot) is coherent with its described usage. However, the install approach (remote installer scripts from a single vendor domain and reliance on a proprietary CLI outside official registries) and the implied data flow to external Dot endpoints introduce notable supply-chain and data-exposure risks. The credential handling is not defined in detail, increasing exposure potential. Overall, the footprint is suspicious and warrants mitigations (verifiable installation from trusted registries, explicit data-flow governance, and explicit credential handling safeguards).

Confidence: 65%Severity: 65%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/Snowboard-Software%2Fgetdot%2Fdot%2F@90fad324dac3a69b7ef9672944011a13560e3b3f