test

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall workflow is coherent for an integration-test-and-deploy skill, and key endpoints (Cloudflare workers.dev, official toolchains) fit the stated purpose. The main risk is proportionate-but-broad credential handling: the skill reads and stores raw OIDC/OpenRouter secrets, passes them to a repo-local deployment script whose internals are not shown, and can modify source code based on external runtime observations. This looks more like a high-risk developer automation skill than confirmed malware.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:26 PM
Package URL
pkg:socket/skills-sh/popmechanic%2Fvibes-cli%2Ftest%2F@cd7c504e9339b4a7ecc8ed9703af498925a9c66d
Security Audit — socket — test