nopal-setup
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities mostly align, and install/network paths appear official, but it materially weakens credential handling by directing export of unmasked Google OAuth credentials into a plaintext file for agent use. This is not confirmed malware, yet it creates a meaningful local credential exposure risk around an external CLI that bundles native binaries.
Confidence: 91%Severity: 63%
Audit Metadata