code-engine-create

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and API/data flows are broadly coherent for Domo Code Engine package creation, and its explicit no-release rule is a positive control. However, the core workflow prefers an external CLI whose official publisher relationship and release provenance were not verified; because that binary is central to execution, the supply-chain risk is disproportionate enough to classify the skill as suspicious rather than benign.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 13, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/stahura%2Fdomo-ai-vibe-rules%2Fcode-engine-create%2F@4c316d6a7920ec72f67e2905a34c077837daff59
Security Audit — socket — code-engine-create