pikvm

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN. The skill is internally consistent with PiKVM remote-management use and sends credentials/data directly to the official PiKVM API on the user-configured host. The primary concern is the pervasive use of insecure TLS bypass (-k), plus the inherent risk of autonomous remote-control and power actions.

Confidence: 94%Severity: 56%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fpikvm%2F@a4b304c97df1f0306a10f8ee23145bb65599ea36331aed792e27eff2190ee0f0
Security Audit — socket — pikvm