kuroco-admin-api

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose largely matches its admin-management capabilities and the target Kuroco domains appear product-consistent, but it relies on a `kuroco-admin` CLI whose public provenance is not verifiably established. Because that CLI handles login-derived session cookies and authenticated admin actions, the install-trust and credential-forwarding risk is high despite otherwise coherent purpose alignment.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 28, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/diverta%2Fkuroco-skills%2Fkuroco-admin-api%2F@8b73f294e83f2a23e9b1fb61ac292cb0b8f8ca17