account-rotation
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the trust boundary is too wide: a credential-rotation skill delegates sensitive account switching to third-party CLIs with mixed provenance, including a non-official raw-script installer. No clear exfiltration path is shown, so this is not confirmed malware, but it is a high-risk credential-handling workflow.
Confidence: 87%Severity: 72%
Audit Metadata