swagger-gen

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This package's declared functionality (LLM-assisted OpenAPI generation from Express routes) is plausible and useful, but it carries moderate supply-chain and data-exfiltration risk. The primary risks are: (1) accidental leakage of proprietary code or embedded secrets because the tool parses handler code and requires an OpenAI API key, and (2) execution-of-remote-code risk when using npx. The README's contradictory statements about API keys and absence of privacy/retention details are red flags. Recommended actions before use: review package source locally, avoid running with sensitive repositories, use temporary API keys with minimal privileges, and request/verify a documented privacy/retention policy from the maintainers.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:17 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fswagger-gen%2F@6de16014608fada0362e84511b0fde9407a1519c