valyd-integration

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent for an identity-integration guide and uses a standard npm SDK, but trust is weakened by the mismatch between publicly visible `valyd.id` materials and the skill’s heavy reliance on `*.valyd.work` runtime/docs hosts for sensitive credentialed traffic. That inconsistency is enough to raise medium risk, though there is no clear evidence of malware, credential theft behavior, or an unrelated capability footprint.

Confidence: 79%Severity: 52%
Audit Metadata
Analyzed At
Sep 2, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/valyd-id%2Fskills%2Fvalyd-integration%2F@b894f801116fa942766275bb01b70facf9e86c39110822b797783852cfb73160
Security Audit — socket — valyd-integration