pypi-doppler

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for local PyPI publishing and uses official tools/endpoints, so it does not look overtly malicious. However, it enables autonomous real-world publishing, forwards PyPI credentials through a third-party secrets manager and local env vars, and includes self-modifying instructions, making it higher risk than a normal documentation-only skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fpypi-doppler%2F@c75a31adcb9d1a07a933a55cb6c2874f5f857c3c