nest-devices

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Report 1 provides a coherent, feature-rich blueprint for Nest Device Access integration that is not intrinsically malicious. However, its security posture hinges on disciplined secret management, minimized external exposure, and verified software supply-chain practices for third-party tools. Improvements should enforce secret rotation, restricted OAuth scopes, authenticated webhook paths, and use of signed, audited deployment artifacts rather than ad-hoc curl installs. With these mitigations, the integration remains technically sound, but current presentation highlights several high-risk patterns needing governance.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:16 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fnest-devices%2F@4cbcf7ba515f8040797a0223da7964e51e9e7997