opencli-usage

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core OpenCLI install and browser-extension flow are broadly consistent with the stated purpose, but the skill meaningfully expands trust by allowing arbitrary plugin installation from git repos and external CLI auto-installs/passthrough. Its authenticated browser access is proportionate to the product goal, yet the overall footprint is larger than a simple orientation skill and carries medium-high operational risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Aug 4, 2026, 04:32 AM
Package URL
pkg:socket/skills-sh/ele-yufo%2FOpenCLI%2Fopencli-usage%2F@1442394f02fac05f55db42cff6d82704980082c6db12eb0a075ba5a5a6834fed
Security Audit — socket — opencli-usage