iblai-api-login

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its ibl.ai login/bootstrap role, and data appears to stay within ibl.ai domains, so it is not clearly malicious. However, it instructs the agent to extract a browser session token from localStorage, use it to mint a long-lived API credential, and write that secret to .env for reuse by other skills; combined with endpoint/documentation inconsistency (api.iblai.app vs platform.iblai.app), this is a meaningful credential-handling risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jul 15, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/iblai%2Fapi%2Fiblai-api-login%2F@f6c09c1e11453736f70c83eac0d12138c4dfc5a4591f964c8d9dbfbdbeb21d36
Security Audit — socket — iblai-api-login