Apptrust Evidence Policies
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and JFrog API usage are mostly aligned and same-vendor, but it weakens trust by instructing the agent to read a local credential file and manually forward a bearer token with curl instead of consistently using the official `jf api` auth flow. Data goes to official JFrog endpoints, so this is not confirmed malware, but the credential-handling pattern creates meaningful security risk.
Confidence: 89%Severity: 58%
Audit Metadata