servel

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s capabilities largely match its stated deployment-platform purpose, but it concentrates extensive remote admin power into a vendor-specific CLI installed via official yet pipe-to-shell instructions. Because the reviewed docs do not provide clear public source verification and the CLI receives deploy tokens and secrets, this is best classified as suspicious/high-risk rather than malicious.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
May 6, 2026, 09:24 AM
Package URL
pkg:socket/skills-sh/K-NRS%2Fservel-skill%2Fservel%2F@8678f88088220d97b2dac37e7d1663ff97ddb55d