happy-platform-skills

Warn

Audited by Socket on May 13, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
skills/genai/ai-lens/SKILL.md

SUSPICIOUS: the core capability is mostly consistent with a ServiceNow contextual-analysis skill and uses first-party ServiceNow API patterns, but the footprint is somewhat broader than necessary due to Bash plus record-write/create actions. Main risk is install/execution trust: the skill depends on unspecified MCP tooling from a third-party publisher without pinned package/version or release verification in the skill itself. No clear credential theft, exfiltration endpoint, or malicious payload is evident.

Confidence: 84%Severity: 52%
AnomalyLOW
skills/admin/workflow-creation/SKILL.md

SUSPICIOUS: The core capability aligns with the stated ServiceNow workflow-creation purpose, and the primary data flows target official ServiceNow APIs rather than an external gateway. Risk comes from credential forwarding into a third-party MCP server, a broken placeholder repo reference, broad admin-level powers, and the ability to deploy arbitrary workflow scripts and publish operational automations.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
May 13, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/happy-technologies-llc%2Fhappy-servicenow-skills%2Fhappy-platform-skills%2F@cbab97c43cb88b262949d1d5a8bec70b72bb81e6
Security Audit — socket — happy-platform-skills