upload

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The alias file is not malicious on its face, but it defers all meaningful behavior to missing skill/auth files, so purpose, credential handling, and network flows cannot be verified. Uploading images to a remote CDN is plausible for the stated purpose, yet the unresolved transitive behavior and weak external provenance justify a suspicious classification rather than benign.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Mar 20, 2026, 12:31 AM
Package URL
pkg:socket/skills-sh/jjenkins%2Fagent-image-skills%2Fupload%2F@c9056a0286ee0774ec454f110b5fb4d2a597ef02
Security Audit — socket — upload