companion-clis

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its Runpod workflow purpose and routes data to expected official endpoints, but it combines broad operational authority with several remote installer patterns and direct credential handling across multiple external CLIs. This looks more like a high-trust operations guide than malware, with medium security risk driven by supply-chain/install hygiene and powerful outward-facing actions.

Confidence: 89%Severity: 60%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/runpod%2Fskills%2Fcompanion-clis%2F@d2e56ee0958de343b6082db61276fd9455596a0e