ngrok
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in purpose and data flow: this is a legitimate ngrok usage skill using official endpoints and vendor-owned distribution. However, it carries HIGH security risk because it depends on a closed-source external binary and can publish local services, including sensitive ports, to the internet if misused.
Confidence: 89%Severity: 72%
Audit Metadata