keeper-secrets

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ksm-exec-patterns.md

No malicious payload or intentional supply-chain attack is evident in this documentation. The main risks are operational: transporting KSM credentials through environment variables, treating base64 as protection, writing resolved secrets to plaintext files, possible secret leakage from logging, and incorrect or incomplete assumptions about automatic resolution in AWS Lambda and services that do not run ksm exec. These issues warrant documentation and deployment hardening but do not indicate malware.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:34 PM
Package URL
pkg:socket/skills-sh/keeper-security%2Fkeeper-agent-kit%2Fkeeper-secrets%2F@0222987121a0cd0ac55de6dc0376e805f404ec7354e35fe6095aba8af3d4e983
Security Audit — socket — keeper-secrets