init-onecli

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but its footprint is not proportionate or trustworthy. It installs an unverifiable external CLI/gateway via `curl|sh`, then reads local credentials and forwards them into that software, creating a strong supply-chain and credential-harvesting risk even though the local-only gateway story sounds legitimate.

Confidence: 88%Severity: 91%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:41 AM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw-skills%2Finit-onecli%2F@8f7fc252750d46f5636c3b049358c800add07b9f