qiaomu-opencli-explorer

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, and the OpenCLI install source appears legitimately same-org. However, the skill is high-impact because it directs an agent to browse arbitrary sites, harvest API behavior from authenticated sessions, intercept requests, generate executable adapters, and potentially publish results. This is not confirmed malware, but it is a medium-high risk automation skill with disproportionate exposure to session credentials and untrusted web content.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Apr 9, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/joeseesun%2Fopencli-skill%2Fqiaomu-opencli-explorer%2F@c0ed04cad6d4324fe61e1a0fd91e406ec296c7a7