ez-ssh

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly aligned with legitimate Home Assistant host debugging and uses direct SSH rather than a third-party gateway, but it weakens SSH security by disabling host key checks and gives somewhat inaccurate/default connection guidance versus Home Assistant's documented host-debug path. Broad host access and sensitive file visibility are proportionate to the purpose, so this is not malware, but it carries meaningful operational and credential-handling risk.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Mar 24, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/araa47%2Fez-ha%2Fez-ssh%2F@b292d4b20b068ed805defcd725719554ba824fb3