extract-tool-registration

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
scripts/verify-tokens.sh

The code is not indicative of classic malware (no persistence, no obfuscated payloads, no dynamic code execution, no reverse shell). However, it is operationally dangerous because it treats API bearer tokens as secrets but explicitly outputs them to stdout and stores response bodies in a predictable shared /tmp file. The primary risk is credential exposure and misuse as a bulk token-testing/collection utility, especially if input files, logs, or environment configuration are not tightly controlled.

Confidence: 80%Severity: 74%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated 'learning/testing' purpose only partially matches the actual footprint. Direct calls to official BibiGPT endpoints are coherent, but the skill’s main value is automating bulk account creation, extracting API keys, and harvesting per-account credits for a companion tool, which is disproportionate to benign UI testing.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Sep 5, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/dithob%2Fmedia-notes%2Fextract-tool-registration%2F@1353b2e1a49bbc6c5ef269e7a7923d7b5b84ba16ec20f6e3aa0b8ae613317a91
Security Audit — socket — extract-tool-registration