ops-settings

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior is broadly consistent with a credential/settings manager, and most data flows go to official service endpoints or official CLIs. However, it centralizes many secrets, performs live credential validation over the network, and includes a Doppler smoke test that installs and runs an npm package on demand with a token in scope, which creates disproportionate supply-chain and credential-forwarding risk for a settings skill.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-settings%2F@aab93b5dae133be2dcc7b82bff7680a31685c68b
Security Audit — socket — ops-settings