miles

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and main capabilities are mostly coherent, but it relies on an opaque bundled CLI that auto-executes via hooks and handles authentication/state without independently verifiable first-party CLI documentation or release provenance. Data flows appear purpose-consistent and not overtly exfiltrative, so this is not confirmed malware, but the unverifiable execution trust and credential-handling opacity make it high security risk.

Confidence: 79%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 12:18 AM
Package URL
pkg:socket/skills-sh/bymilesai%2Fskills%2Fmiles%2F@ca1a45edf25d37a4c6632eed8743b34c09f60b81