crxhub-cli

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent, and GitHub is the expected backend, but the skill's core action is executing an unverifiable bundled binary under an authenticated GitHub CLI context. That makes the install/execution trust disproportionate to the simple extension-management task and creates meaningful credential and supply-chain risk.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 25, 2026, 12:44 PM
Package URL
pkg:socket/skills-sh/xxww0098%2Fskills-hub%2Fcrxhub-cli%2F@c16db13f9d1d00a065da3670259acb14c72926c4