5dive-cli

Warn

Audited by Socket on Aug 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated purpose as a 5dive runtime control surface, but it grants broad orchestration power through a vendor-specific opaque local CLI, supports delegated external actions (chat/GitHub), and includes a shell-mediated messaging path. No direct malware indicators, credential theft, or remote installer behavior appear in the skill text itself, but the operational scope and trust centralization make it medium-to-high risk.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Aug 10, 2026, 11:17 PM
Package URL
pkg:socket/skills-sh/5dive-ai%2Fskills%2F5dive-cli%2F@350df5bec618576e4fe809c06e7e688475a41199088a00b81367699d98711d1d
Security Audit — socket — 5dive-cli