init-onecli
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, but its footprint is not proportionate or trustworthy. It installs an unverifiable external CLI/gateway via `curl|sh`, then reads local credentials and forwards them into that software, creating a strong supply-chain and credential-harvesting risk even though the local-only gateway story sounds legitimate.
Confidence: 88%Severity: 91%
Audit Metadata