ambit-cli

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign overall with moderate risk regarding credential scope and ACL management. The ambit-cli skill aligns with its stated purpose of creating/destroying private networks, deploying apps, and managing access within a Tailnet/Fly.io context. Credential needs and ACL changes are legitimate for the domain but require careful least-privilege configuration and user awareness to avoid broad access exposure. No clear evidence of malicious data exfiltration or insecure third-party binaries; however, automatic ACL modifications and one-shot ACL policy surface outputs should be clearly documented to prevent misconfiguration. Treat as SUSPICIOUS in terms of potential policy-misconfiguration risk but not malicious given current data flows and sources.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:45 PM
Package URL
pkg:socket/skills-sh/ToxicPine%2Fambit-skills%2Fambit-cli%2F@c050ff222613859c73f32bc02218410597db90bf