mono-cli

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose as a mono service CLI, and its npm-based install path is more normal than a raw downloader. However, package provenance is not verified from the evidence, the installed CLI receives/stores PAT credentials, and --base-url can redirect authenticated traffic. This is not clearly malicious, but it carries medium risk and should only be used if the package publisher and official documentation are independently confirmed.

Confidence: 78%Severity: 61%
Audit Metadata
Analyzed At
Mar 20, 2026, 06:27 AM
Package URL
pkg:socket/skills-sh/kyaukyuai%2Fmono-cli-skill%2Fmono-cli%2F@4806a639752fa21a36f3686d2c66ede58c220ad9