openerp-shared

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functional scope matches an ERP query/auth skill and the stated API destinations look consistent with Kingdee K3Cloud, but the entire workflow hinges on an unverifiable openerp binary that receives app secrets and session tokens. That makes the skill high risk on install/execution trust and credential forwarding grounds even without evidence of explicit exfiltration.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Aug 25, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/xiaowen-0725%2Fopenerp-cli%2Fopenerp-shared%2F@5e61ae432207634f46ef46371b460f6d9e52520343d3c7b6b1d118d1461c01ba
Security Audit — socket — openerp-shared