jfrog-init

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/claude-config.mjs

This module is a local credential migration utility that extracts a token from the URL password component of matching marketplace/source entries, converts it into an `Authorization: Bearer ...` header, removes credentials from the URL, and overwrites the user’s Claude marketplace configuration files atomically. There is no direct evidence of malware behaviors in this snippet (no network calls, no command execution), but it performs security-sensitive handling and persistence of authentication material and suppresses errors, so its behavior should be reviewed in the broader context of how/why `moveTokenToHeader()` is invoked.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Sep 8, 2026, 04:04 PM
Package URL
pkg:socket/skills-sh/jfrog%2Fjfrog-skills%2Fjfrog-init%2F@b05eb5e1863bce2e337f966043f8865c838ffe21f9a9d90da8deb3a2a9257c46
Security Audit — socket — jfrog-init