opencli

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's main capabilities broadly match its stated browser-to-CLI purpose, and the npm install path looks legitimate. However, the scope is high-risk because it reuses authenticated browser sessions, auto-discovers tokens, supports account-changing/public actions, and encourages exploration of arbitrary websites with write/exec-like agent capabilities. Not confirmed malware, but it is a high-risk agent skill.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 17, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/mxyhi%2Fok-skills%2Fopencli%2F@ef7c0ee394dfcfe82249223abc816126ff8e9a52