ai-news

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill appears to be a developer-focused CLI for AI News with dynamic server-loaded commands and integrations (Flomo). Overall purpose-capability alignment is reasonable, but key security concerns exist around dynamically loaded server commands (possible remote code execution), flexible API endpoint configuration (potential data-path manipulation), and token handling during authentication. Data flows for URL analyses and webhook interactions are expected but require strict privacy controls and secure handling. The footprint is suspicious enough to warrant careful review before broad deployment, particularly around remote command execution risk and token lifecycle management.

Confidence: 58%Severity: 52%
Audit Metadata
Analyzed At
Mar 12, 2026, 10:26 AM
Package URL
pkg:socket/skills-sh/strzhao%2Fai-news-cli%2Fai-news%2F@24f1f7298a89ea233fbbd620948b5990e837d5bc