xgg-rule-authoring

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities largely match its stated purpose, but its footprint is high-impact because it lets an AI agent perform authenticated, live home-automation changes and household-behavior capture. The main trust concern is reliance on a non-verifiably Xiaomi-official xgg CLI, including optional execution from local build output, which makes the install/execution chain and credential handling less trustworthy than the vendor-focused purpose suggests.

Confidence: 83%Severity: 71%
Audit Metadata
Analyzed At
Aug 1, 2026, 01:06 PM
Package URL
pkg:socket/skills-sh/eyaeya%2Fxiaomi-central-hub-gateway-cli%2Fxgg-rule-authoring%2F@9a41faed536a2738cb0f486fb6ad6a1e2e5dddb2bfc7f2e1e7572181d729026f
Security Audit — socket — xgg-rule-authoring