leapcat-auth

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functions match its stated authentication purpose, but it relies on an unverified external `leapcat` CLI and sends sensitive authentication material to that black-box binary. With no confirmed official install source or documented data path, the supply-chain and credential-forwarding risk is high even without direct evidence of malware.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:36 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-auth%2F@e4dc92ad97f0a42f92304687c8c5555098b24f87
Security Audit — socket — leapcat-auth