buildin-cli
Warn
Audited by Socket on Jul 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its Buildin API purpose and routes data to Buildin-owned domains, but it relies on remote installer execution for a private/closed-source CLI and then uses that CLI with bearer-token authentication. This is not clearly malicious, yet the install-trust and credential-forwarding model creates meaningful medium risk.
Confidence: 82%Severity: 58%
Audit Metadata