doppler-secret-validation

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Doppler usage is broadly consistent with the stated purpose and relies on official Doppler tooling, so this is not strongly indicative of malware. However, the skill handles raw secrets, can forward them to arbitrary API URLs, includes self-modifying instructions, and references another skill, which together raise meaningful security risk beyond a minimal secret-validation helper.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:53 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fdoppler-secret-validation%2F@461a56bfc890686cef36823678cfae254d20491f