happy-platform-skills

Warn

Audited by Socket on Aug 5, 2026

4 alerts found:

Anomalyx4
AnomalyLOW
skills/grc/regulatory-alert-analysis/SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses official ServiceNow-style APIs, with no external installer or obvious exfiltration path. Risk is driven by broad ServiceNow privileges and arbitrary Background Script execution, which are powerful but plausibly related to the stated GRC analysis task.

Confidence: 89%Severity: 58%
AnomalyLOW
skills/grc/issue-validator/SKILL.md

SUSPICIOUS: The skill’s purpose and ServiceNow data access are coherent for GRC validation, and there is no direct exfiltration or malware behavior in the skill text. Risk comes from reliance on powerful background-script execution and unverified third-party MCP tooling that may receive ServiceNow credentials and data, making this medium-risk rather than benign.

Confidence: 84%Severity: 61%
AnomalyLOW
skills/legal/contract-metadata-extraction/SKILL.md

SUSPICIOUS. The core data access aligns with contract metadata extraction and the documented network targets are official ServiceNow APIs, but the skill grants broader-than-necessary powers through custom/unverified MCP wrappers, background-script execution, and unused Bash capability. This looks more like an overprivileged enterprise automation skill than malware.

Confidence: 84%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS. The root skill is mostly coherent as a catalog/discovery entry and uses a same-org npm/GitHub distribution path, but it explicitly installs and loads a large transitive set of additional skills. That broad trust expansion is disproportionate for a simple catalog skill and should be treated as medium risk until the child skills are separately reviewed.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Aug 5, 2026, 02:48 PM
Package URL
pkg:socket/skills-sh/Happy-Technologies-LLC%2Fhappy-servicenow-skills%2Fhappy-platform-skills%2F@fe67d3be5344f862dc2fc6c107eaf7bd027090e4
Security Audit — socket — happy-platform-skills