socc-deploy

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The README itself contains no embedded malicious code, but it instructs a supply-chain-sensitive workflow that involves downloading and executing a third-party npm package and providing an API token. The main risks are: (1) executing unreviewed remote code (supply-chain compromise), (2) potential credential capture or insecure token storage, and (3) accidental or malicious exfiltration of files beyond the intended build directory. Recommend auditing the socclink package and dependencies, using isolated execution environments, verifying token storage/usage, and ensuring the working directory contains only intended artifacts before deploying.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 11:00 AM
Package URL
pkg:socket/skills-sh/soccagency%2Fsocc-skill%2Fsocc-deploy%2F@2041a0d641ab426866b3067a18ffa4c36826f2bf