apiiro-threat-model

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and behavior are largely coherent and proportionate, but it depends on an external CLI whose specific install path and release provenance are not established in the provided evidence. No clear malicious behavior, credential harvesting, or proxy data routing is shown, so this is mainly a supply-chain trust concern rather than confirmed malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/apiiro%2Fcli-releases%2Fapiiro-threat-model%2F@bdfe11a7561434bdedc0c784713dcd58b87fcb48