exa

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but its implementation relies on a third-party personal `api2cli` tool to generate and handle the Exa CLI and credentials. Official Bun installation only partly mitigates risk; the unpinned third-party CLI generation and credential forwarding make the overall security posture medium-high risk.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 23, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/Melvynx%2Fexa-cli%2Fexa%2F@5e13cc79c503e2208239781377726ccf767359b7