javascript-sdk

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The JavaScript SDK skill is coherent with its stated purpose: it provides a legitimate npm-based SDK for interacting with inference.sh, supports API key usage, environment-based credentials, file uploads, streaming, and proxy patterns for frontend apps. The footprint is appropriately scoped to development tooling and API integration, with no evident supply-chain or credential-exfiltration risks beyond standard API key handling. Recommend BENIGN with note to implement secure handling of API keys in client apps and to verify proxy configurations in deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/toolshell%2Fskills%2Fjavascript-sdk%2F@0249e98aefe2476063bfa18bd85aa30df0b62e53