cli-anything-chromadb

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated ChromaDB-management purpose and its data flow appears limited to the ChromaDB API, but the install trust is weak because the CLI is a third-party wrapper from HKUDS/CLI-Anything rather than an official Chroma distribution path, and the claimed PyPI package could not be verified from the checked URL. This is a supply-chain risk more than evidence of malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/HKUDS%2FCLI-Anything%2Fcli-anything-chromadb%2F@5c02d73b6949aa98b49c5133df69244295a190fa
Security Audit — socket — cli-anything-chromadb