apiiro-threat-model

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and behavior are largely coherent and proportionate, but it depends on an external CLI whose specific install path and release provenance are not established in the provided evidence. No clear malicious behavior, credential harvesting, or proxy data routing is shown, so this is mainly a supply-chain trust concern rather than confirmed malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/apiiro%2Fmarketplace%2Fapiiro-threat-model%2F@bdfe11a7561434bdedc0c784713dcd58b87fcb48