xapi

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s broad purpose matches its features, but its trust footprint is large. It installs and executes an external CLI, routes many third-party API calls through xapi’s own infrastructure, forwards API/OAuth authority to that intermediary, and supports real-world actions including social posting, SMS procurement, and payments. This is not clearly malicious, but the intermediary data flows and credential/power concentration make it a high-trust skill that is risky for an autonomous agent.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 28, 2026, 02:10 PM
Package URL
pkg:socket/skills-sh/xapi-labs%2Fxapi-cli%2Fxapi%2F@c81a02258b02970d1dedcf8fba21ed22c69c0fdc