api-to-agent-cli

Warn

Audited by Socket on Oct 7, 2026

1 alert found:

Security
SecurityMEDIUM
assets/example-hello-cli/SKILL.md

SUSPICIOUS: the skill’s purpose and actions mostly align with a todo CLI, and the documented commands are not themselves malicious. However, the core `hello-cli` dependency is unverified and the service endpoint is undisclosed, so credential and data flows cannot be validated; this drives a high supply-chain/security-risk classification rather than confirmed malware.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Oct 7, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/aws-samples%2Fsample-aws-ops-skills-for-agents%2Fapi-to-agent-cli%2F@a0fb3a105d88162a343fe64429600998a01116e5f3dd75cc9e2733ccd3d4965a