one-actions
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the general API-integration workflow, but the skill's actual footprint is high risk because it depends on an unspecified external CLI and routes sensitive cross-platform actions through One's proxy. The broad real-world action scope is plausible for the purpose, yet the missing CLI provenance and intermediary data flow make this unsafe to treat as benign.
Confidence: 81%Severity: 82%
Audit Metadata