ops-go

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's business-ops purpose is coherent, but its actual footprint is broader than a simple dashboard: it executes several unverifiable local binaries, accesses multiple communication/account surfaces through third-party CLIs, and can trigger follow-on task/schedule actions. The strongest concern is install/execution trust for the opaque ops-* binaries; absent provenance, checksums, or source linkage, this must be treated as high security risk even without proof of malicious intent.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-go%2F@11db6b3294112ae41707d2b7303055f8fc081e3e