apiiro-risks

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose and capabilities are coherent for a repository risk-inspection tool, and it does not obviously overreach on credentials or actions. However, it depends on a required external `apiiro` CLI whose official public distribution and command documentation could not be verified from the supplied evidence, so this should be treated as suspicious from an install-trust/supply-chain standpoint rather than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/apiiro%2Fcli-releases%2Fapiiro-risks%2F@8a7e84055d41eb6e0547abd7cdf19e8499a7088a