pypi-doppler
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly coherent for local PyPI publishing and uses official tools/endpoints, so it does not look overtly malicious. However, it enables autonomous real-world publishing, forwards PyPI credentials through a third-party secrets manager and local env vars, and includes self-modifying instructions, making it higher risk than a normal documentation-only skill.
Confidence: 88%Severity: 58%
Audit Metadata