livekit-cli

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The provided document is benign guidance for using the LiveKit CLI. No explicit malicious code or instructions to exfiltrate data are present in this text. Primary security concerns are operational: (1) use of an unverified 'curl | bash' installer pattern which introduces supply-chain risk if the installer or its host is compromised, and (2) guidance that writes API secrets to local files without recommending secure storage or verification steps. To fully evaluate malicious or unwanted behavior, audit the remote installer script (https://get.livekit.io/cli) and the installed lk binary's runtime/network behavior. Until those are reviewed, treat the documentation as low-risk but apply standard supply-chain and secret-management precautions.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:14 PM
Package URL
pkg:socket/skills-sh/codestackr%2Flivekit-skills%2Flivekit-cli%2F@e1066b656e5389075df991cbb2b8e817fd5b2531