taruvi-backend-provisioning

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely purpose-aligned for Taruvi backend administration and shows no clear third-party exfiltration or malicious install chain, but it grants an AI agent a very broad control-plane footprint and explicitly instructs credential creation and disclosure in final outputs. The biggest risks are autonomous impactful actions and password exposure, not malware.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:17 AM
Package URL
pkg:socket/skills-sh/Taruvi-ai%2Ftaruvi-skills%2Ftaruvi-backend-provisioning%2F@40fe31c96a3e588bb6be3f3cc8c11bfe5cc8a712