music-assistant

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent with music-control capabilities and the declared data flow points to the user's own Home Assistant environment, but the skill's core ha-ma executable is not installable from any verified source in the provided evidence. Because that unverifiable CLI would receive a long-lived Home Assistant token, the skill carries high security risk despite otherwise plausible scope.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
Mar 20, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skill%2Fmusic-assistant%2F@81c98c43aba242018189bd1b309bed6ba0834d54