kernel-cli

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This README describes a legitimate CLI with powerful, high-privilege features for managing cloud browser sessions and executing user code remotely. No explicit malicious code, obfuscation, or hardcoded credentials are present in the provided documentation. However, the combination of remote execution, filesystem operations, extension uploads, and proxy control creates a substantial attack surface if credentials (API key or OAuth token) are compromised or if the distributed package is tampered with. The document lacks details about fine-grained scopes, endpoint transparency, and secure defaults — omissions that increase supply-chain and operational risk. Recommend treating API keys as high-value credentials, enforcing least-privilege scopes, rotating keys, enabling audit logging, and reviewing the actual CLI implementation and network endpoints before trusting the package in sensitive environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/kernel%2Fskills%2Fkernel-cli%2F@61792ac8b180725e218feb362b08f46831dc76d1