saudi-shipping

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose and capabilities mostly align with a Saudi shipping integration guide, and it does not install external code. However, it forwards sensitive credentials and shipment PII to remote APIs, includes real-world shipment-creation actions, uses insecure HTTP for SMSA, and references a J&T endpoint whose official relationship to the Saudi onboarding domain is not clearly verified.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
Jul 7, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/Moshe-ship%2Fhurmoz%2Fsaudi-shipping%2F@2a1836c6cefbba55b2415f4bcdd4ea3de623137360cff90fe2ec9f16152107e7
Security Audit — socket — saudi-shipping