eightctl

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill shows coherence with its stated purpose of controlling Eight Sleep pods but exhibits notable security concerns: unverified binary installation from a GitHub source, dual credential surfaces (config.yaml and env vars) with potential exposure, and undocumented API endpoints. These factors yield a suspicious to high-risk profile due to credential handling and supply-chain uncertainties. Recommend tightening by using verifiable, signed releases from official registries, documenting and constraining credential access, and detailing TLS/endpoint security and token handling.

Confidence: 62%Severity: 68%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:40 PM
Package URL
pkg:socket/skills-sh/letta-ai%2Flettabot%2Feightctl%2F@b1ef976f0c7010f8cae46490385dda8b25e45b53