exe-dev
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. Most SSH/HTTPS API usage aligns with exe.dev VM management, but the skill also bootstraps machines by running an unpinned personal GitHub `curl|bash` script while forwarding a Tailscale auth key from 1Password into that process. The main concern is supply-chain trust and credential forwarding to third-party code, not confirmed malware.
Confidence: 89%Severity: 86%
Audit Metadata