NYC

testing-production

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md file appears functionally consistent with its stated purpose (production validation using live services). I found no code-level backdoors, obfuscation, or hardcoded secrets. However, it requests many high‑sensitivity credentials, runs actual networked operations (DB, Redis, SMTP, payment APIs), and persists reports to an external agent memory API (mcp__claude-flow__memory_usage). Those behaviors are appropriate for a production‑validation tool but carry moderate supply‑chain and data‑exfiltration risk if executed in uncontrolled or malicious CI contexts. Recommend: treat credentials with least privilege, redact sensitive data before storing reports, vet any external npx packages (claude-flow@alpha), and run validations in isolated, auditable environments (staging accounts, scoped API keys).

Confidence: 80%Severity: 55%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:37 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Ftesting-production%2F@8608c29b1be905bd1940b625ef10e3e3cbdca2bd