rpi

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align as a lifecycle orchestrator, but it is highly autonomous, expands trust to multiple sub-skills, and depends on at least one locally invoked CLI (ao) whose public provenance is not verifiable from the supplied evidence. No direct credential theft, exfiltration, or malicious payload execution is evident in this skill text.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 20, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Frpi%2F@88bd22f78cc78ef2e26e959d386e46a634618c96