cli-anything-firefly-iii

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose and requested credential type are coherent with a Firefly III CLI, and data appears intended to flow directly to the user's own Firefly III instance rather than a proxy. The main issue is install trust: the package name could not be verified on PyPI and the publisher relationship is unclear, so the distribution path is not well substantiated. Broad finance/admin operations and webhook management increase impact if the package is not what it claims. Overall this is better classified as suspicious due to unverifiable package provenance, not confirmed malicious behavior.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
May 13, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/HKUDS%2FCLI-Anything%2Fcli-anything-firefly-iii%2F@7049c85bccc354261118a9d89590438688c34c99
Security Audit — socket — cli-anything-firefly-iii