actrun-init

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, but it asks the agent to install and trust an external CLI via a pipe-to-shell path, pass secrets into that CLI, and optionally schedule recurring workflow execution. This looks more like a high-risk developer tooling skill than clear malware, with the main concerns being install trust, credential exposure to actrun/workflow steps, and broad local code execution.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/mizchi%2Factrun%2Factrun-init%2F@7c18f31159bbf3daca1d62e4d70213f3df65902e
Security Audit — socket — actrun-init