cyrus-setup-endpoint
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and data flows are mostly coherent for webhook exposure, but it installs and relies on a proprietary external tunnel binary and forwards credentials to it. This is not confirmed malicious, yet the install-execution and credential-forwarding footprint is high enough to warrant elevated risk.
Confidence: 88%Severity: 80%
Audit Metadata