sigcli-auth-proxy

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Internally consistent with its stated purpose: this is an auth proxy skill, and the credential extraction, proxying, and injection features belong to that purpose. It is not confirmed malware, and the install source appears official, but the skill is high risk because it gives an AI agent broad access to sensitive browser/session credentials, supports MITM proxying, can forward secrets into arbitrary commands, and even documents SSL-verification bypasses.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 17, 2026, 11:54 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fsigcli-auth-proxy%2F@1dc4fbee34760f108806cc53ef3252b0810a9e69