xgg-rule-authoring
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s capabilities largely match its stated purpose, but its footprint is high-impact because it lets an AI agent perform authenticated, live home-automation changes and household-behavior capture. The main trust concern is reliance on a non-verifiably Xiaomi-official xgg CLI, including optional execution from local build output, which makes the install/execution chain and credential handling less trustworthy than the vendor-focused purpose suggests.
Confidence: 83%Severity: 71%
Audit Metadata