app-studio-build

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is coherent for building Domo App Studio assets, but its entire footprint depends on an unverified external CLI that likely handles Domo credentials and performs privileged tenant mutations. There is no clear evidence of malicious exfiltration, yet the unresolved provenance of community-domo-cli makes the install/execution trust and credential-forwarding risk high.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:06 PM
Package URL
pkg:socket/skills-sh/stahura%2Fdomo-ai-vibe-rules%2Fapp-studio-build%2F@a9a24c90d12972b7e6bc2a083671eb6e77a5b1fb