m5-onboard
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities largely match its device-onboarding purpose, and data flow stays aligned with flashing/provisioning. The main concern is install trust: it relies on an unpinned personal GitHub repo for the shipped scripts/app bundle and may bootstrap tooling via package managers or GitHub downloads. No strong signs of credential theft, covert behavior, or unrelated exfiltration were found, but the host/device modification footprint is broad enough to warrant medium risk.
Confidence: 88%Severity: 56%
Audit Metadata