pylot-api

Warn

Audited by Socket on Jul 25, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose mostly matches its capabilities, but it routes sensitive tokens and conversation context to a private gateway whose operator and official documentation could not be publicly verified from the evidence. No confirmed malware or overt exploit behavior is present, but the unverifiable backend trust boundary, hidden-failure instruction, and operational side effects make this higher-risk than a normal documentation/API helper skill.

Confidence: 81%Severity: 68%
SecurityMEDIUM
docs/secrets.md

No explicit malicious payload behavior (backdoor, persistence, third-party exfiltration, or obfuscated logic) is evident in the provided fragment. The main concern is dual-use: it demonstrates how to authenticate to a privileged /admin/secrets endpoint to enumerate secret key metadata and to write secret values. If the bearer token or endpoint access is compromised or abused, this capability can materially enable credential reconnaissance and secret injection.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Jul 25, 2026, 05:28 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fpylot-api%2F@798b78409fca401aafcda547a9286ef594a2b76e4e95d87d863b8d1ba631ca11
Security Audit — socket — pylot-api