crxhub-cli

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s trust model is not. It asks the agent to execute an unverifiable bundled binary and use it with the user’s authenticated GitHub CLI context while fetching arbitrary third-party release assets. No overt exfiltration endpoint is shown, but the opaque binary and credential-adjacent access create high security risk.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Mar 14, 2026, 10:46 AM
Package URL
pkg:socket/skills-sh/xxww0098%2Fskills-hub%2Fcrxhub-cli%2F@4045da16bd5f845cabaab43fd3473a31a49c0f6b