migrate-litellm-to-portkey
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly coherent as a migration guide, and the main Python package/source relationships appear legitimate. However, it intentionally reroutes prompts and authentication through Portkey’s intermediary gateway, encourages storing provider credentials in Portkey-managed infrastructure, and includes unverified `npx portkey` commands. This is not clearly malicious, but it has meaningful trust and data-flow risk beyond a simple SDK swap.
Confidence: 87%Severity: 58%
Audit Metadata