agent-tools
Audited by Socket on Mar 12, 2026
1 alert found:
AnomalyOverall, the skill is purpose-aligned with orchestrating a broad AI app ecosystem via a centralized CLI. However, its installation pattern (curl | sh) and potential credential handling for external services introduce notable security considerations. The data flows involve uploading local files to cloud apps and posting to social platforms, which are expected for this tool but require explicit secure handling and clear user consent. Given the combination of remote installation, broad API access, and multi-service data flows, the risk profile is elevated; classify as SUSPICIOUS with a leaning toward BENIGN depending on implementation details (e.g., solid credential management, explicit user prompts, strict data handling policies).