credential-switch

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s core credential operations are outsourced to undocumented local scripts that receive and switch sensitive tokens. No direct exfiltration or obviously malicious endpoint is shown, yet the unverifiable credential-handling dependency makes this a high security-risk skill.

Confidence: 81%Severity: 80%
Audit Metadata
Analyzed At
Apr 1, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fcredential-switch%2F@47dd7cd356638724f382bb7479ecfc6ff8c457b6