crony

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the runtime behavior is mostly aligned with a cron-management skill, but the install trust is not. The key issue is the unverifiable `uv tool install agentcli-helpers` dependency and mismatch with the separately documented public `crony-cli` distribution. No clear credential theft or off-platform data exfiltration is shown, but the skill installs unclear third-party code and grants persistent arbitrary command execution on the host.

Confidence: 86%Severity: 80%
Audit Metadata
Analyzed At
May 19, 2026, 11:00 AM
Package URL
pkg:socket/skills-sh/lirrensi%2Fagent-cli-helpers%2Fcrony%2F@dc7eb07d3165cbdba4b83d7235395edb969eca7c
Security Audit — socket — crony