anki-ai-cli

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s Anki-focused capabilities mostly match its stated purpose and default to a local Anki-Connect flow, but trust is weakened by runtime execution of an unpinned `npx` package whose official provenance was not established in the evidence. Broad destructive actions and a configurable non-local endpoint raise security risk, though there is no clear credential harvesting or confirmed malicious behavior.

Confidence: 77%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 06:36 AM
Package URL
pkg:socket/skills-sh/briansunter%2Fanki-ai%2Fanki-ai-cli%2F@871c4ee5baa44089d87ee376870cfa6f4f7cb626
Security Audit — socket — anki-ai-cli