coze-api

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (Coze API integration for chat and workflows) is coherent with its capabilities and data flows. It relies on standard API calls to official endpoints and uses tokens for authentication, which is expected for such integrations. Minor security concerns arise from sample code showing hard-coded PAT usage and potential credential exposure in logs or stdout if not properly managed. Overall, the footprint is proportionate to the stated purpose, with moderate risk primarily around credential handling practices and secure secret management. No evidence of malicious behavior or improper exfiltration beyond legitimate API use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:38 PM
Package URL
pkg:socket/skills-sh/staruhub%2FClaudeSkills%2Fcoze-api%2F@f9b884a9312e806e2a14f483e8e0ce467d704e95