griffin-cli

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill fragment is purpose-aligned and presents a coherent, non-destructive workflow for using Griffin CLI in JSON mode with explicit auth flow and non-interactive guarantees. The main risk vectors are standard for CLI-based hub interactions: local credential storage (~/.griffin/credentials.json) and per-environment secrets on the hub. There is no evidence of malicious behavior, hidden exfiltration, or unauthorized data access beyond what is typical for a CLI managing monitors and secrets. Recommend monitoring for proper access controls on local credential storage and ensuring hub endpoints are trusted and authenticated.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/griffin-open-source%2Fskills%2Fgriffin-cli%2F@7c553f9e97cfc15907cd87bb33197171930a26fc