opencli-rs

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core idea is coherent, but its footprint is overly broad for a browsing helper. Same-org install evidence lowers malware confidence, yet the combination of raw curl|sh installation, Chrome-session reuse, broad personal-data access, arbitrary site extension, passthrough to other CLIs, and high-impact autonomous actions makes this a high-risk agent skill.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/nashsu%2Fopencli-rs-skill%2Fopencli-rs%2F@a2519815f0742d848d0ad8e7d1e2eb22ad176bec