anki-ai-cli
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s Anki-focused capabilities mostly match its stated purpose and default to a local Anki-Connect flow, but trust is weakened by runtime execution of an unpinned `npx` package whose official provenance was not established in the evidence. Broad destructive actions and a configurable non-local endpoint raise security risk, though there is no clear credential harvesting or confirmed malicious behavior.
Confidence: 77%Severity: 72%
Audit Metadata