crxhub-cli
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill’s trust model is not. It asks the agent to execute an unverifiable bundled binary and use it with the user’s authenticated GitHub CLI context while fetching arbitrary third-party release assets. No overt exfiltration endpoint is shown, but the opaque binary and credential-adjacent access create high security risk.
Confidence: 87%Severity: 83%
Audit Metadata