join

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior mostly matches its stated purpose: it asks for the tenant key, calls a cloud identity endpoint, and writes local config. The main concern is install trust: it executes an unpinned package that directly receives the credential, and the exact @catalyst-cloud/catalyst-skills package provenance was not fully verifiable from the provided evidence. No clear malicious exfiltration is shown, but the credential-forwarding and partially unverifiable package trust chain make this higher risk than a typical setup helper.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Sep 10, 2026, 08:08 AM
Package URL
pkg:socket/skills-sh/coalesce-labs%2Fcatalyst-cloud-skills%2Fjoin%2F@0c8f21fb8e47211ce1ba51c1a71f094c47bb3dfb324f1ab9f8d6ee0bccde6be3
Security Audit — socket — join