tuckmark-agent-import-user

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is broadly consistent with an inventory-import skill and includes privacy-preserving instructions, but it requires an unverifiable external CLI with unclear provenance and credential handling. That makes the main risk supply-chain trust rather than confirmed malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 8, 2026, 11:29 AM
Package URL
pkg:socket/skills-sh/ivanli-cn%2Ftuckmark%2Ftuckmark-agent-import-user%2F@46f1a0d15e99677f896d1852429373f24ad67e134001eefe26df05bed30feb5f
Security Audit — socket — tuckmark-agent-import-user