kimi

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior matches its stated purpose, and upstream Kimi CLI provenance is reasonably verifiable through official MoonshotAI channels and package registries. However, it adds meaningful risk by relying on the x-cmd wrapper auto-install path and by encouraging YOLO auto-approval, which can let an AI coding agent execute actions with reduced user oversight. No clear credential theft, covert exfiltration, or incompatible capability was shown.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fkimi%2F@563a5f0cbaee58cc5b8cd4afee8cb2bf66376440