cc-connect-ai-bridge

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core bridge concept is coherent, but the skill materially expands an AI agent's remote-control surface by exposing local agents and shell-capable workflows to external messaging input. The biggest concerns are transitive AI-driven installation from a raw GitHub document and indirect prompt injection/autonomous command execution via chat, not confirmed malware or overt credential theft.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 28, 2026, 04:22 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fcc-connect-ai-bridge%2F@942b24ec45ff884157e5cd57aad1462661562675