5dive-cli
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is largely coherent with its stated purpose as a 5dive runtime control surface, but it grants broad orchestration power through a vendor-specific opaque local CLI, supports delegated external actions (chat/GitHub), and includes a shell-mediated messaging path. No direct malware indicators, credential theft, or remote installer behavior appear in the skill text itself, but the operational scope and trust centralization make it medium-to-high risk.
Confidence: 82%Severity: 66%
Audit Metadata