opencli-oneshot
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses same-org OpenCLI tooling, so it is not clearly malicious. However, it teaches an agent to inspect arbitrary websites, reuse session credentials/tokens, capture network traffic, and generate executable adapters from untrusted external content, which is a medium-risk capability set for a one-shot helper skill.
Confidence: 82%Severity: 56%
Audit Metadata