openerp-shared
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The functional scope matches an ERP query/auth skill and the stated API destinations look consistent with Kingdee K3Cloud, but the entire workflow hinges on an unverifiable openerp binary that receives app secrets and session tokens. That makes the skill high risk on install/execution trust and credential forwarding grounds even without evidence of explicit exfiltration.
Confidence: 88%Severity: 84%
Audit Metadata