anylist

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its trust model is not: it asks for raw AnyList email/password and routes them through a CLI that could not be verified as official AnyList software. Because a third-party or unofficial CLI receives account credentials, the main concern is credential forwarding and supply-chain risk rather than overt malicious behavior.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:25 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fanylist%2F@9737337d848ff407f8c18663b6d425da67c9f4e5