homey
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities match smart-home control and its data flows appear aimed at official Homey APIs, so it is not fundamentally deceptive. However, the trust boundary is broader than ideal because credentials are handed to a non-officially-verified CLI name (homeycli), and the skill enables impactful real-world actions. Overall this looks coherent but medium risk due to credential forwarding and actuator control.
Confidence: 81%Severity: 56%
Audit Metadata