sub-cli
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but it relies on an unverified external CLI that receives Substack cookies and performs authenticated actions. Because the CLI provenance and official distribution path were not confirmed, and the skill even encourages self-updating to the latest release, the install-trust and credential-forwarding risks are disproportionate to the available verification evidence.
Confidence: 83%Severity: 84%
Audit Metadata