ramp-data-handling
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose is legitimate and its credential use broadly fits Ramp API integration, but it has notable integrity issues: credentials are sent to a host fully controlled by RAMP_BASE_URL, the sample auth/path details do not match Ramp's documented endpoints, and the skill grants broader Bash execution capability than the example requires. No direct malware or installer payload is present, but the combination of unchecked endpoint construction and broad tool scope makes it medium risk.
Confidence: 86%Severity: 58%
Audit Metadata