valet
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with managing Valet agents, but its footprint is powerful. Main concerns are moderate supply-chain trust for installation, remote Git/source ingestion, and especially credential forwarding through `valet exec` into third-party commands and services. The behavior is coherent for a deployment/orchestration skill, but it warrants medium-high security caution rather than a benign rating.
Confidence: 81%Severity: 68%
Audit Metadata