cost-export

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated observability-export purpose, and there is no installer or obvious hidden payload. However, it sends internal telemetry to arbitrary external webhooks and can forward Authorization headers to those endpoints, making data-flow trust the main risk. This is not confirmed malware, but it has medium-high security risk due to external export and credential-forwarding potential.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
May 5, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fcost-export%2F@10cd75cb98333266eccd6020bb86383d19d59e65