cli-auth

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches an auth-management CLI, and the requested token/endpoint are broadly proportionate. The main issue is install/execution trust: the skill relies on an unresolved `csdk` binary with no documented provenance, while verified same-org evidence points to differently named executables. Combined with arbitrary endpoint routing of auth tokens and powerful account-management actions, this creates medium security risk without enough evidence for confirmed malicious intent.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
May 9, 2026, 03:53 AM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive%2Fcli-auth%2F@271af24232ebbee1902871e058cb818ad3c5b45a
Security Audit — socket — cli-auth