ravi-login

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent for identity-based signup/login automation, and the Ravi CLI provenance appears same-org official, but it gives the agent high-impact capabilities: retrieving stored passwords, reading OTP/email verification content, and completing third-party account actions. No clear credential-harvesting proxy is shown, so this is not confirmed malicious, but the autonomy and credential scope make it high-risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/ravi-hq%2Fravi-skills%2Fravi-login%2F@dc21faaec0c6520043eea2fee388c7afc0559a0f