crxhub-cli
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose is coherent, and GitHub is the expected backend, but the skill's core action is executing an unverifiable bundled binary under an authenticated GitHub CLI context. That makes the install/execution trust disproportionate to the simple extension-management task and creates meaningful credential and supply-chain risk.
Confidence: 83%Severity: 76%
Audit Metadata