eightctl-hardened
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities fit its stated purpose, but it asks the agent to trust a personal unofficial CLI with account credentials and real-world device control. Because install is source-based from a verifiable repo and data appears aimed at Eight Sleep endpoints, this is not confirmed malware; the main concerns are third-party credential trust, unofficial API use, and unpinned installation.
Confidence: 89%Severity: 66%
Audit Metadata