vault-api
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely purpose-aligned and behaves like documentation for Vault API usage, with no malware-style installer or hidden execution. However, it is a third-party skill covering highly privileged secret-management operations and it routes credentials to an external gateway domain whose ownership is not verified, creating a medium data-flow and trust concern.
Confidence: 89%Severity: 52%
Audit Metadata