account-rotation

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the trust boundary is too wide: a credential-rotation skill delegates sensitive account switching to third-party CLIs with mixed provenance, including a non-official raw-script installer. No clear exfiltration path is shown, so this is not confirmed malware, but it is a high-risk credential-handling workflow.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:35 AM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Faccount-rotation%2F@7d6341164c7a21693aa821df14381df6973da4cdb5142544d6f5eaf395ae931a
Security Audit — socket — account-rotation