qiaomu-opencli-usage
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core npm install appears legitimate and same-project, so this is not confirmed malware, but the skill’s footprint is broad for a 'usage guide': authenticated browser automation, desktop app access, passthrough to powerful external CLIs, transitive plugin/skill trust, and limited autonomous self-repair. These capabilities can fit OpenCLI’s stated purpose, yet they create medium-high security risk and deserve caution.
Confidence: 86%Severity: 69%
Audit Metadata