companion-clis
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its Runpod workflow purpose and routes data to expected official endpoints, but it combines broad operational authority with several remote installer patterns and direct credential handling across multiple external CLIs. This looks more like a high-trust operations guide than malware, with medium security risk driven by supply-chain/install hygiene and powerful outward-facing actions.
Confidence: 89%Severity: 60%
Audit Metadata