qiaomu-opencli-usage

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core npm install appears legitimate and same-project, so this is not confirmed malware, but the skill’s footprint is broad for a 'usage guide': authenticated browser automation, desktop app access, passthrough to powerful external CLIs, transitive plugin/skill trust, and limited autonomous self-repair. These capabilities can fit OpenCLI’s stated purpose, yet they create medium-high security risk and deserve caution.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:04 PM
Package URL
pkg:socket/skills-sh/joeseesun%2Fqiaomu-opencli-skills%2Fqiaomu-opencli-usage%2F@7f4d390b2d6de1f99b8f60f61f434b7856db3cc3333f9cf6ac7ef14a71c4df2c
Security Audit — socket — qiaomu-opencli-usage