platform-metadata-api-context-get

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
assets/metadata_api/ConnectedApp.json

This snippet is not evidence of active malware execution, but it is high-sensitivity OAuth/SAML configuration that embeds credential-like secrets and certificates directly, alongside several security-relevant policy choices (notably infinite refresh tokens) and multiple HTTP URLs in authentication/federation contexts. Treat as a significant supply-chain/secret-exposure and auth-configuration hygiene risk, especially if these values are real and included in any published artifact or repository.

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Aug 7, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fplatform-metadata-api-context-get%2F@8e66a0cef9f93ce534c0217a3724014de80da1739cad622c037fef19cde59506
Security Audit — socket — platform-metadata-api-context-get