astria-api
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and API-related capabilities are coherent, and data appears intended for Astria’s official service, but it requires a non-publicly-verifiable `astria` CLI that reads local credentials and receives uploaded files. Under the mandatory override for unverifiable executables receiving credentials, this is high security risk even without clear evidence of malicious intent.
Confidence: 86%Severity: 84%
Audit Metadata