woblehelp

Connect Socket

Agents score npm, PyPI and cargo packages, inspect published files and read your org's supply-chain alerts; you connect by signing in with Socket.

SocketSign inDeveloper

Score npm, PyPI and cargo packages, surface supply-chain alerts.

Once Socket is connected, an agent can score a dependency before suggesting it (supply chain, quality, maintenance, vulnerability and licence signals), open the files inside a published package when a score looks off, and list the open alerts and threat feed entries for your Socket organization.

Before you start

  • A Socket account at socket.dev. The free plan is enough for package scores and package file inspection.
  • To read alerts and the threat feed, your account has to belong to a Socket organization (the one your repositories are scanned under).
  • You must be an owner or admin of the woble workspace. Members see the integration but cannot connect it.

Connect it

  1. Open Marketplace, choose the Integrations tab, find Socket and press Connect.
  2. Press Continue with Socket. A new tab opens at socket.dev.
  3. Sign in the way you normally do (GitHub, GitLab, Bitbucket or email).
  4. Socket asks you to authorize woble. The request covers listing packages, listing alerts and reading the threat feed for your organizations. Press Authorize.
  5. The tab closes and the card says Connected. The agent panel lists the Socket tools: dependency scores, package files, organizations, alerts and threat feed.

There is no API token to copy; the sign-in covers everything.

Or ask an agent

Type @ruby connect Socket in any chat. The same connect card appears in the conversation. Only owners and admins can complete it.

Try it

  • "@atlas score these before I add them: fastify, undici and pino. Anything under 20?"
  • "@atlas what open Socket alerts do we have on the web repo, and which ones are malware or typosquats?"

If it does not connect

  • Signed in to the wrong Socket account: the alerts tools show an organization you do not expect, or none at all. Press Remove in Marketplace → Connected and connect again with the account that belongs to your organization.
  • Scores work but alerts fail: your account is not a member of a Socket organization, or the organization has no scanned repositories yet. Join or create one at socket.dev first.
  • Session expired or access revoked in Socket's settings: press Test connection in Marketplace → Connected. If it fails, Remove and reconnect.

Disconnect

Marketplace → Connected → Socket → Remove. The stored tokens are deleted and agents lose the Socket tools immediately.

More in this category

On this page