buildin-cli

Warn

Audited by Socket on Jul 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its Buildin API purpose and routes data to Buildin-owned domains, but it relies on remote installer execution for a private/closed-source CLI and then uses that CLI with bearer-token authentication. This is not clearly malicious, yet the install-trust and credential-forwarding model creates meaningful medium risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jul 6, 2026, 06:27 AM
Package URL
pkg:socket/skills-sh/next-space%2Fbuildin-skill%2Fbuildin-cli%2F@a735673a610dd8512cdfa6539e115b3f6c759fc6e25635c2ba592ab0c8ca0e82
Security Audit — socket — buildin-cli