crony
Warn
Audited by Socket on May 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the runtime behavior is mostly aligned with a cron-management skill, but the install trust is not. The key issue is the unverifiable `uv tool install agentcli-helpers` dependency and mismatch with the separately documented public `crony-cli` distribution. No clear credential theft or off-platform data exfiltration is shown, but the skill installs unclear third-party code and grants persistent arbitrary command execution on the host.
Confidence: 86%Severity: 80%
Audit Metadata