fizzy

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with a legitimate Fizzy admin/workflow CLI, but its footprint is high-impact: it can perform destructive and admin operations, accepts tokens from multiple sources, documents temporary token file handling, and can route data to arbitrary webhook URLs or a custom API endpoint. Nothing here proves malware, but the combination of wide account control and configurable outbound destinations raises meaningful security risk for an AI agent skill.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/robzolkos%2Ffizzy-cli%2Ffizzy%2F@345a4d33fe801c991bf7bb12292584fe82efd7bc
Security Audit — socket — fizzy