llm-models

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign overall given the stated purpose of enabling multi-model LLM access through a single CLI surface. The footprint—CLI-based installation, runtime prompts routed to OpenRouter/model endpoints, and no embedded credential harvesting or unverifiable binaries—fits a legitimate developer tooling scenario. The primary security considerations are data privacy and trust in the external OpenRouter endpoints, not credential exposure or supply-chain risk. Recommend adding explicit data handling/privacy notes and ensuring users are aware prompts are sent to external services.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 12:14 PM
Package URL
pkg:socket/skills-sh/toolshell%2Fskills%2Fllm-models%2F@7194a7cac075f8383c3de3d75d7341f57a4bb61b