alapi

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose and official API destination are coherent, but the skill's credential workflow is not: it directs users to obtain/manage tokens through a third-party Apifox page instead of ALAPI's own documented console, asks the user to send the token back to the agent, and persists it in plaintext shell startup files. There is no strong evidence of malware or malicious exfiltration, but the token-handling and acquisition path are inconsistent enough to raise medium security concern.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/wangyendt%2Fwayne-skills%2Falapi%2F@771f0e07d60693fcd6ce4d7b40beef8d3c18c781