spellcaster-cli

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment is coherent with its stated purpose: it guides generation of spellcaster CLI commands and config handling for operators. There are no evident malicious behaviors, no uncontrolled downloads, and no credential harvesting mechanisms embedded. The primary risk is potential leakage of configuration details if the user exposes them; the skill itself avoids executing anything autonomously beyond presenting commands. Overall, the security risk is low to moderate (benign to suspicious if misused), with no malware indicators evident.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/MakinaHQ%2Fmakina-agents%2Fspellcaster-cli%2F@66335551b68bea402c4542dcc86954cdfecc7c63