ambit-cli

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated infrastructure-management purpose and mainly targets official Fly.io and Tailscale workflows, but it carries meaningful security risk from npx download/execute, storage and use of high-privilege tokens, and especially deployment of third-party GitHub templates with mutable refs. I see no clear evidence of credential harvesting or malicious exfiltration, but the trust chain is wider than ideal and should be treated as high-impact automation.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 25, 2026, 08:49 PM
Package URL
pkg:socket/skills-sh/ToxicPine%2Fambit-skills%2Fambit-cli%2F@df66fe5252f5f7e7261d76d88a3d3d52e083107b