cli-anything-hub

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS rather than malicious: the hub itself appears to be published through legitimate same-org PyPI/GitHub channels, but its main purpose is to broker installation of many additional CLI packages from a live remote catalog. The verified provenance lowers concern for the base package, yet the marketplace-style transitive install model and broad scope create meaningful supply-chain risk.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fcli-anything-hub%2F@9565eaf5ed08a2bd61d06387d66c8bcac8d00c1c
Security Audit — socket — cli-anything-hub