iot-fleet
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the capability matches the stated IoT fleet purpose, but the skill's entire function relies on executing an unpinned npm package at runtime via npx -y @latest. This is mainly a supply-chain and remote-action trust issue, with no direct evidence of credential theft or exfiltration in the skill text.
Confidence: 81%Severity: 64%
Audit Metadata