climate-generator

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated purpose, but it materially expands an agent's footprint by turning remote OpenAPI input into generated code/binaries and enabling GitHub publication with tokens. The main concerns are untrusted-spec-to-code generation, credential forwarding to an external CLI, and real-world publishing actions; there is no clear evidence of credential harvesting or deceptive exfiltration.

Confidence: 81%Severity: 57%
Audit Metadata
Analyzed At
Apr 17, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/disk0Dancer%2Fclimate%2Fclimate-generator%2F@e80c7057ad0150c4ab224563e04c98ec5c1bca66
Security Audit — socket — climate-generator