opencli-autofix

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it lets the agent process untrusted live website content and then autonomously edit local code and rerun commands. There is no obvious credential harvesting or off-platform exfiltration, so this is not malicious, but the read-external/write-local loop creates medium security risk.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/jackwener%2Fopencli%2Fopencli-autofix%2F@33e74b9833e2cc217d20d6b769c3e3278757fe0d