cli-anything

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's general purpose is coherent, but its key differentiator—the CLI-Anything harnesses—has a publisher/provenance mismatch and vague executable install path. Standard brew/npm tools are normal, yet the repo-to-PATH harness installation is insufficiently verified and raises meaningful supply-chain risk without clear evidence of malicious intent.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/HR-AR%2Fclaude-code-skills%2Fcli-anything%2F@cbdde9145c6de94e1d0d443856123f16c613aef9
Security Audit — socket — cli-anything