maintainx-debug-bundle

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/implementation-guide.md

The fragment appears to be legitimate diagnostic and validation tooling, not malware. The main security risk is that verbose curl logging can save the MAINTAINX_API_KEY to maintainx-debug.log, and the support bundle copies recent logs without redaction despite advising users not to share API keys. Logs and support bundles should be sanitized before storage or sharing, and authorization headers should be suppressed or redacted.

Confidence: 96%Severity: 55%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fmaintainx-debug-bundle%2F@8d9eee0d59c64ff4330f430e8b6577e2ab55d86834de70714084cbfaa4919716
Security Audit — socket — maintainx-debug-bundle