secrets-vault-manager

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/vault_config_generator.py

The code appears intended as a Vault configuration generator, not malware. It contains serious correctness issues that likely prevent execution as supplied. If repaired, it would write configuration and shell scripts containing insecure placeholder credential patterns, optional disabled TLS/audit logging, broad permissions, and potentially dangerous provisioning commands. The unchecked authentication-method input creates a plausible path-traversal risk when constructing output filenames. No direct data theft, network exfiltration, command execution, or backdoor behavior is shown.

Confidence: 94%Severity: 67%
Audit Metadata
Analyzed At
Sep 19, 2026, 02:19 AM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fsecrets-vault-manager%2F@626fe73a1dc3ab37cea94fa513ef79f88fa9617f7a44d061323f84f7d923fa52
Security Audit — socket — secrets-vault-manager