awiki-people

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is mostly a placeholder contract with no direct exfiltration or credential handling, and its planned people features fit the stated purpose. The main risk is execution trust: it grants Bash access to awiki-cli while the binary's provenance is not verifiable from the provided evidence, plus it relies on another local skill for behavior. Because the commands are not implemented and no credentials or external endpoints are shown, this is not malicious, but it remains medium/high security risk due to the unverifiable CLI trust boundary.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 12, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/agentconnect%2Fawiki-cli%2Fawiki-people%2F@332a3c1eeff22ce10e9155aee779acc239bb8015
Security Audit — socket — awiki-people