eightctl

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest itself is not executable source code and contains no immediate malicious code, but it introduces moderate supply‑chain and credential exposure risk because it instructs fetching an unpinned external Go module (module@latest) and uses raw email/password stored in env vars or a local config. Recommend auditing the upstream repository, pinning releases, verifying network endpoints/telemetry, and switching to tokenized/authenticated approaches if available before trusting credentials.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/QVerisAI%2FQVerisBot%2Feightctl%2F@ce61977c3cfaed61bf9d44b929786f3b621025d8