revor-company-research

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The research purpose and Revor data flows are mostly coherent and use official Revor endpoints, so this does not look like confirmed malware. But the skill’s explicit instruction to solicit an API key in chat and write it to persistent local config is disproportionate and contrary to safer auth practices, and the fallback client script was not available for review. Overall this is a medium-risk skill with notable credential-handling concerns, not a clearly benign documentation-style integration.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Sep 10, 2026, 01:35 PM
Package URL
pkg:socket/skills-sh/laiye-revor%2Frevor-skills%2Frevor-company-research%2F@573f0789b47b0167f4e36548a3558873a4bd98dec1ea53a318574ef9a9055980
Security Audit — socket — revor-company-research