scout-manual-workflow

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for a bug-tracker workflow, but its data-flow model is risky: it sources secrets from local .env files and sends the Scout API key to a fully user-configured SCOUT_URL rather than a pinned official endpoint. The external actions are proportionate to the stated purpose, yet the unrestricted endpoint and raw credential handling make this a medium/high security-risk skill rather than a clearly benign one.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 18, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/scout-dev-org%2Fscout%2Fscout-manual-workflow%2F@96591645f9e5e0b83420c1f7e6b82ce5aeb13130
Security Audit — socket — scout-manual-workflow