10x-cli-setup

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill delegates execution-critical behavior to a live, unpinned README fetched at runtime. That creates medium supply-chain risk because future upstream README changes could alter what the agent installs or runs, even though the source is same-org GitHub and there is no direct credential harvesting or overt exfiltration in the skill itself.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 02:41 PM
Package URL
pkg:socket/skills-sh/przeprogramowani%2F10x-cli%2F10x-cli-setup%2F@101a19453a7564e5afb493edb8d27401602783b4