local-places

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill/payload appears to be benign given its stated purpose as a local development proxy for Google Places data. The main security considerations are standard: protect the API key, ensure the local server is not exposed beyond localhost, and implement basic access controls and rate limiting if extended beyond local use. No suspicious download/install patterns or credential forwarding to third-party tools are evident in the fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Flocal-places%2F@bee0d3996bb0204eaf7961624f261988e17e0c3f