vault-process

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core vault-processing behavior is internally consistent and local-only, but the optional execution of an unverified external command (vault-qmd) is not well supported by the evidence and creates disproportionate install/execution trust risk. No clear credential theft or exfiltration is present, so this is not confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 12, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/markphelps%2Fagent-plugins%2Fvault-process%2F@9fecd1bfd46db9f206313fafbbac208c7fc9f19f
Security Audit — socket — vault-process