da-auth
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and Adobe-only data flow are coherent, but it relies on executing a GitHub-sourced helper that handles OAuth tokens without strong release-verification signals. This looks more like a risky same-org auth helper than malware; medium risk comes from supply-chain trust and token-handling exposure, not clear exfiltration.
Confidence: 83%Severity: 56%
Audit Metadata