devto-translator

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent, but the skill relies on running unpinned code from a personal GitHub repository, forwards two API keys into that code, and enables automatic public posting. This is a high supply-chain and credential-forwarding risk, not confirmed malware.

Confidence: 85%Severity: 86%
Audit Metadata
Analyzed At
Jul 25, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/kkdai%2Fagent-skill-hub%2Fdevto-translator%2F@44a6c3e07a665752565eac43279ac31124d9edaeb26239220c72a3483835b22f
Security Audit — socket — devto-translator