av-cli

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an operational instruction file for using the Aviator 'av' CLI to manage stacked pull request workflows. Its capabilities (reading av/av.db, invoking av and git commands, interacting with remotes) are consistent with the stated purpose. There are no direct signs of malware, remote exfiltration endpoints, obfuscated code, or download-and-execute chains inside the provided content. The main risks are operational: the skill instructs agents to run commands that can push to remotes and manipulate repository state (which uses existing git credentials) and it assumes the av CLI is trusted and already present — if an agent autonomously installs or fetches an av binary from an untrusted source that would increase supply-chain risk. Overall, the content appears appropriate for the declared purpose but should only be used in environments where av is installed from a trusted source and where the agent's ability to push or create PRs is intentionally permitted and controlled.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/aviator-co%2Fagent-plugins%2Fav-cli%2F@f101c0aa638fed130bbcf5a7b97f78632b4d1105