ai-agent

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of configuring AI agents with flows, webhook tools, and knowledge bases. It uses standard API key patterns for provider access and webhook secrets for tooling integration. The risk profile is low-to-moderate, driven primarily by credential handling in examples and external network interactions; no evidence of download-execute supply chain, autonomous real-world actions, or credential forwarding to unverifiable binaries. Recommend ensuring secure handling of API keys/webhook secrets, explicit per-action user consent for webhooks, and access controls/logging to minimize data exposure. Overall, classify as BENIGN with careful credential hygiene.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/zavudev%2Fzavu-skills%2Fai-agent%2F@b578287ba12d40e101896f31e5feebb01d899491