qiaomu-opencli-usage

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches a powerful browser/app automation tool, but the footprint is broad: it reuses live sessions, supports real-world account actions, ingests untrusted content, auto-installs external CLIs, and encourages automated self-repair plus related-skill chaining. No clear evidence of malware or hidden exfiltration, but the security risk is high because the scope and delegated trust are substantial.

Confidence: 85%Severity: 81%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/joeseesun%2Fqiaomu-opencli-skills%2Fqiaomu-opencli-usage%2F@b6d0fb6fa121c34fc20abe07a86dd24c111be7a8