use-ryvn
Warn
Audited by Socket on May 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The operational scope largely matches the stated Ryvn infrastructure purpose, and the visible data flows appear same-org, but the skill requires a proprietary `ryvn` CLI whose install provenance could not be verified and then encourages passing login or service-account credentials into it. Broad shell permissions and automatic feedback submission further increase risk. This looks more like a high-risk, internally coherent admin skill than confirmed malware.
Confidence: 84%Severity: 83%
Audit Metadata