astria-api

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and API-related capabilities are coherent, and data appears intended for Astria’s official service, but it requires a non-publicly-verifiable `astria` CLI that reads local credentials and receives uploaded files. Under the mandatory override for unverifiable executables receiving credentials, this is high security risk even without clear evidence of malicious intent.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
May 18, 2026, 04:16 PM
Package URL
pkg:socket/skills-sh/astriaai%2Fskills%2Fastria-api%2F@dfc07e3d14f2258acda0e8a7e806190067c211bd
Security Audit — socket — astria-api