nopal-setup

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and install/network paths appear official, but it materially weakens credential handling by directing export of unmasked Google OAuth credentials into a plaintext file for agent use. This is not confirmed malware, yet it creates a meaningful local credential exposure risk around an external CLI that bundles native binaries.

Confidence: 91%Severity: 63%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/fivetaku%2Fnopal%2Fnopal-setup%2F@f929b68561e731b2c2157272f1da93666095104f
Security Audit — socket — nopal-setup