redis-js

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content aligns with its stated purpose of guiding and using the Upstash Redis JS SDK. It uses standard, well-known distribution (npm) and documents environment-variable-based credential usage, which is appropriate for development tooling. No evidence of data exfiltration, credential harvesting, or unauthorized remote actions beyond normal SDK usage. The only notable caution is that sample code includes placeholder tokens, which is expected in documentation but should be clearly marked as non-secret. Overall, the footprint is Benign with moderate caution around credential handling in samples.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 06:57 PM
Package URL
pkg:socket/skills-sh/upstash%2Fupstash-redis%2Fredis-js%2F@9fcecfcf2a0e1d665695de7bc46c133fafb34766