cyrus-setup-endpoint

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and data flows are mostly coherent for webhook exposure, but it installs and relies on a proprietary external tunnel binary and forwards credentials to it. This is not confirmed malicious, yet the install-execution and credential-forwarding footprint is high enough to warrant elevated risk.

Confidence: 88%Severity: 80%
Audit Metadata
Analyzed At
Mar 22, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/ceedaragents%2Fcyrus%2Fcyrus-setup-endpoint%2F@220c1e23a4f0a7c95369d78ce16c45a7feef017d