agent-job-secrets

Warn

Audited by Socket on May 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its behavior, but that behavior is high-risk: it enables an AI agent to enumerate and retrieve secrets and refreshed OAuth tokens via an unspecified remote endpoint. No obvious malicious installer is present, yet the combination of credential access, remote retrieval, and unverified APP_URL makes this a sensitive skill that should be treated as medium-high security risk rather than benign.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 22, 2026, 04:19 PM
Package URL
pkg:socket/skills-sh/stephengpope%2Fthepopebot%2Fagent-job-secrets%2F@9632fd8e4d445c5443cee44491c3e27d407b7381
Security Audit — socket — agent-job-secrets