blucli

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's described functionality (BluOS device discovery/control) is coherent with its stated purpose. However, it relies on installing an unverifiable binary from a GitHub module (@latest) without checksums or a trusted registry, which introduces a significant supply-chain risk and potential credential/data exposure risk if the binary is compromised or malicious. The data flows to local device endpoints are normal for this purpose, but the install/execution path is not trustworthy. Recommend replacing with an officially published, signed binary or container image from a trusted registry, and include integrity checks (checksums/signatures) and version pinning.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:12 PM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fopenclaw-composio%2Fblucli%2F@b5c70749d9ce2cf8ef0de037dd0c83560861be14