secrets

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose broadly matches secret management, but its actual footprint relies on an unverifiable `secrets` CLI and forwards credentials into unnamed CLI/MCP processes. Missing install provenance and opaque downstream executables make the trust and data-flow model disproportionate for a security-sensitive skill.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Fsecrets%2F@0677d3a34b72e77fd7aabdc75d0a9bb7c2e330d0