spaces-storage

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This code is a benign set of example integrations for DigitalOcean Spaces. It contains no signs of malware or supply-chain credential-harvesting. Primary risks are operational/security misconfiguration: default public ACLs (public-read) which publicly expose uploaded objects, lack of filename sanitization, and the general risk of mishandling long-lived access/secret keys. Those are configuration/usage risks to address (use private ACLs when appropriate, validate filenames, limit key permissions and rotate keys).

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/vanman2024%2Fai-dev-marketplace%2Fspaces-storage%2F@55e9e307d2e1a10be160976046cc3e38e7775e5d