informe-cli
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose broadly matches an internal company-agent gateway, and the `uv`/`cloudflared` prerequisite sources are official. However, the core capability depends on a private, mutable GitHub-installed CLI that cannot be independently verified, then uses company authentication and can upload local files and query sensitive internal systems; `inf setup` also overwrites the local skill copy. That combination makes the skill high risk even without confirmed malicious intent.
Confidence: 91%Severity: 84%
Audit Metadata