blink-connectors
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's broad API execution capability is aligned with its stated OAuth-connector purpose, and the install/source relationship appears same-org and documented. The main concern is architectural: all connected-service traffic and server-side OAuth token use flow through Blink as an intermediary, and the generic exec interface can perform real-world actions across many providers. This is coherent for a managed connector platform, but higher-risk than direct official API use because it concentrates credential and data access in Blink's backend.
Confidence: 85%Severity: 52%
Audit Metadata