sesame
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent, but its core model routes authenticated API traffic through an intermediary broker and external CLI instead of official APIs. Without strong install-provenance evidence for secretctl, this creates high supply-chain and credential-forwarding risk; it looks more like a risky auth gateway than malware.
Confidence: 84%Severity: 84%
Audit Metadata