nopeek

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is plausible, but the skill’s core design undermines its claim: users must pass secrets into an unverified, unpinned external CLI fetched via `pnpx`. Automatic Claude Code hooks further increase blast radius. This is not confirmed malware, but it is a high-risk supply-chain and credential-forwarding skill.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
May 8, 2026, 10:00 PM
Package URL
pkg:socket/skills-sh/spences10%2Fskills%2Fnopeek%2F@29227e258bfe6b2ed2c35ffb1804f83074440efa