cbi-repo

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s actions are broadly consistent with its stated purpose: repository/project/portfolio management through a vendor-specific CLI. I found no clear exfiltration endpoint, covert behavior, or purpose mismatch. However, the core dependency is an external `cbi` CLI whose public installation source, release history, and verification trail are not established by the evidence provided. Because the skill requires this unverifiable CLI and relies on authenticated login/session handling, its overall risk is high under the mandated scoring rules, even without evidence of confirmed malicious intent.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
May 8, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/CreatiBI%2Fcli%2Fcbi-repo%2F@06f565e95aa57cae20e4da792bf351e1a308a3fc
Security Audit — socket — cbi-repo