gamma-upgrade-migration

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the migration purpose is plausible, but the skill’s core package installs are not verified against Gamma’s official docs, which instead document direct API usage. Installing unverified SDK packages and then passing `GAMMA_API_KEY` to them creates a material supply-chain and credential-forwarding risk, even though the rest of the workflow is a normal upgrade guide.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fgamma-upgrade-migration%2F@d47c9d05c7f6756ef0f648ec03200870119367cb
Security Audit — socket — gamma-upgrade-migration