omni-version-manager
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core localhost service-management behavior is aligned with the stated purpose, but the skill has meaningful security risk because it installs several external services, one package triggers an additional binary download, and Dario explicitly imports and stores OmniRoute Claude OAuth tokens in another service's account store. The footprint is mostly coherent, but credential forwarding and expanded third-party trust make it higher risk than a normal local admin skill.
Confidence: 85%Severity: 68%
Audit Metadata