iblai-agent-api

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with a UI integration skill, but it expands trust through CLI upgrades, MCP installation, mutable raw-GitHub downloads, and automatic command execution. I found no clear credential harvesting or malicious exfiltration, so this looks more like medium supply-chain/trust risk than malware.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:07 PM
Package URL
pkg:socket/skills-sh/iblai%2Fvibe%2Fiblai-agent-api%2F@0c3bdab9fc6e6d46f96772848b8f708a52cb58cb