puff

Fail

Audited by Socket on Mar 13, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but its core execution path relies on a personal third-party `puff` CLI rather than official OpenAI tooling. There is no clear evidence of credential theft or proxy exfiltration, yet the install trust model and authenticated wrapper behavior create medium security risk.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/tkersey%2Fdotfiles%2Fpuff%2F@24a870db5dc4cd06d5fa46bd68e057133043e4b0