valyd-integration
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent for an identity-integration guide and uses a standard npm SDK, but trust is weakened by the mismatch between publicly visible `valyd.id` materials and the skill’s heavy reliance on `*.valyd.work` runtime/docs hosts for sensitive credentialed traffic. That inconsistency is enough to raise medium risk, though there is no clear evidence of malware, credential theft behavior, or an unrelated capability footprint.
Confidence: 79%Severity: 52%
Audit Metadata