opencli-operate

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned but high-impact: it grants an agent broad browser automation over arbitrary sites using existing authenticated sessions, plus extraction of page/API data and local code writing. No clear credential-harvesting or third-party exfiltration is shown, so this is not confirmed malware, but the combination of authenticated browsing, untrusted web content, and write/exec-adjacent capability makes it a medium-high risk skill.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 4, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/jackwener%2Fopencli%2Fopencli-operate%2F@ea5cac5bb3f22840520bdc3f90f6a68c7f86f6d3