kelly-listing

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/publish_airapp.mjs

This module is a legitimate-looking deployment/publishing CLI, but it performs a high-impact bulk read-and-upload of nearly all files under a local directory to Busabase via publishAirApp. There is no obvious malware/backdoor logic in the snippet; however, the broad file selection without extension/type allowlisting makes accidental or abusive data exfiltration/publishing plausible if sensitive artifacts exist under appRoot or if credentials point to the wrong workspace.

Confidence: 66%Severity: 54%
Audit Metadata
Analyzed At
Aug 25, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/mr-kelly%2Fskills%2Fkelly-listing%2F@ff6773595fc2c8a4ac3442111b7e35926161921ec8f8178583df053813b83070
Security Audit — socket — kelly-listing