spots

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Installation of third-party script detected Benign with caveats. The fragment aligns with a legitimate tool for exhaustive Google Places searches and reveals standard credential handling patterns. The primary concerns are secure handling of API keys and avoiding inadvertent exposure in logs or outputs; ensure the actual implementation enforces secure secret handling and minimal privilege usage. LLM verification: The provided SKILL.md describes a legitimate CLI utility that requires Google Places & Geocoding API access and instructs installation from GitHub. The document itself contains no explicit malicious code or hard-coded secrets, but it does present supply-chain and credential-exposure risks: installing unpinned remote code and handing a sensitive API key to a third-party binary. Without the repository source code and dependency tree, it is not possible to rule out credential exfiltration or other

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 07:25 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fspots%2F@abc689bd76cebf07771fba564ae347814c85365d