informe-cli

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches an internal company-agent gateway, and the `uv`/`cloudflared` prerequisite sources are official. However, the core capability depends on a private, mutable GitHub-installed CLI that cannot be independently verified, then uses company authentication and can upload local files and query sensitive internal systems; `inf setup` also overwrites the local skill copy. That combination makes the skill high risk even without confirmed malicious intent.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Sep 7, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/mindlogic-ai%2Fvibe-kit%2Finforme-cli%2F@6ab5b549f84beacfa29472ed5ac7493f30296afc0cd86ea6426ea0b44d4ce761
Security Audit — socket — informe-cli