service-de-channel-activate

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
references/phone-verification.md

No clear malicious or supply-chain attack behavior is present. The workflow is consistent with WhatsApp phone verification through Salesforce. It presents moderate security risks because the OTP is placed in a query string and command invocation, and because predictable /tmp output files are used without documented secure creation, permissions, or cleanup. Use URL encoding, strict allowlist validation, secure temporary files, and avoid exposing the OTP in shell history or process listings.

Confidence: 95%Severity: 55%
Audit Metadata
Analyzed At
Aug 28, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fservice-de-channel-activate%2F@2c47024358f9f7c3aee6b45fb46a1c32ce9ad99bdcd446cfc352c178290b20f5
Security Audit — socket — service-de-channel-activate