letta-configuration

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup_provider.py

The code is an overt provider-registration utility with no clear malware indicators, obfuscated payloads, persistence, or unauthorized system access. Its principal security risks are transmitting credentials to any user-selected server, using HTTP by default, and exposing secrets through command-line arguments. These risks warrant remediation in production use, especially by requiring HTTPS, validating or allowlisting the server, and accepting secrets through safer mechanisms. The exact fragment also contains an apparent syntax error at the end.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:47 PM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fletta-configuration%2F@2fb88ddd174659775cd4c97aba2806db800f67cb6ce51a2d797a8867bad6206c
Security Audit — socket — letta-configuration