eightctl

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill shows coherence with its stated purpose of controlling Eight Sleep pods but exhibits notable security concerns: unverified binary installation from a GitHub source, dual credential surfaces (config.yaml and env vars) with potential exposure, and undocumented API endpoints. These factors yield a suspicious to high-risk profile due to credential handling and supply-chain uncertainties. Recommend tightening by using verifiable, signed releases from official registries, documenting and constraining credential access, and detailing TLS/endpoint security and token handling.

Confidence: 62%Severity: 68%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:28 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Feightctl%2F@b1ef976f0c7010f8cae46490385dda8b25e45b53