phase-4-api

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent API-development guidance, but it expands into a third-party remote MCP/BaaS integration that can receive project data and credentials. No confirmed malware or covert exfiltration is evident, yet the external trust chain and credential forwarding to bkend create medium security risk.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:25 PM
Package URL
pkg:socket/skills-sh/popup-studio-ai%2Fbkit-claude-code%2Fphase-4-api%2F@dc30f7978abecf15df4333474d8a7cbabafcb108