music-connect

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's overall purpose is coherent, but it asks the agent to download and execute an npm package at runtime and hand it a live Cognitum PAT. The main concerns are mutable `@latest` installation, incomplete publisher/provenance verification for `cogmusic`, and credential forwarding to third-party code; absent stronger evidence that the package is officially owned by Cognitum, this is higher-risk than a normal documentation/setup skill.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Aug 27, 2026, 10:24 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fmusic-connect%2F@99f48cbd3a4740e5c096d53a43d1fc4b3df6d1217863a3e5d2d39d2ad7bad86a
Security Audit — socket — music-connect