bifrost-platform

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's operational scope matches a deployment assistant, but its install path is inconsistent with Bifrost's official documentation: it directs the agent to install a different npm publisher's CLI and then use that binary for authentication, deployment, and infrastructure actions. That package provenance mismatch is the dominant risk and is sufficient to treat the skill as high-risk even without confirmed malicious payloads.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Apr 6, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/chandrashekhar-appointy%2Fbifrost-agent-skills%2Fbifrost-platform%2F@bd84c8a43b1cee3cc0aa20238692ce8daa96b9e8
Security Audit — socket — bifrost-platform