one-actions

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the general API-integration workflow, but the skill's actual footprint is high risk because it depends on an unspecified external CLI and routes sensitive cross-platform actions through One's proxy. The broad real-world action scope is plausible for the purpose, yet the missing CLI provenance and intermediary data flow make this unsafe to treat as benign.

Confidence: 81%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/picahq%2Fcli%2Fone-actions%2F@c5190413ffbe155330de6e9e52cbe71eb6865193
Security Audit — socket — one-actions