mo-shared

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent for a CLI helper, but its footprint includes a required external binary (`mocli`) whose publisher, install path, and release provenance could not be verified. Because the skill also forwards an API key to that unverifiable CLI, the risk is materially elevated even without explicit malicious behavior in the instructions.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
May 8, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/mowenxd%2Fcli%2Fmo-shared%2F@14eb1edbc3b38b82215de69215459b92c34d3f52