opencli

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches social-site browsing/interaction, but the skill’s actual footprint is too broad and trust-poor: it relies on an unverifiable external CLI, uses the user’s authenticated Chrome session as implicit credentials, enables private-data access and public posting, and expands itself by generating new site scrapers. The main issue is not classic malware proof, but disproportionate account access and opaque third-party code handling sensitive session-derived data.

Confidence: 83%Severity: 84%
Audit Metadata
Analyzed At
Mar 16, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/joeseesun%2Fopencli-skill%2Fopencli%2F@0b992152c5dc3fa0a4b0c73459e14be6b1a77679