cli-anything-eth2-quickstart

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the capability set mostly matches the stated Ethereum node-management purpose, but it grants an agent high-impact infrastructure actions including public RPC exposure and execution of external shell scripts from a repo whose provenance is not established in the provided text. No clear credential theft or exfiltration is evident, so this looks more like a high-risk ops skill than confirmed malware.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/HKUDS%2FCLI-Anything%2Fcli-anything-eth2-quickstart%2F@7728d927c533cbab00bfb46406629c1484101e3b
Security Audit — socket — cli-anything-eth2-quickstart