spellcaster-cli
Warn
Audited by Socket on Feb 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill fragment is coherent with its stated purpose: it guides generation of spellcaster CLI commands and config handling for operators. There are no evident malicious behaviors, no uncontrolled downloads, and no credential harvesting mechanisms embedded. The primary risk is potential leakage of configuration details if the user exposes them; the skill itself avoids executing anything autonomously beyond presenting commands. Overall, the security risk is low to moderate (benign to suspicious if misused), with no malware indicators evident.
Confidence: 75%Severity: 75%
Audit Metadata