agent-message-cli
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly match its messaging purpose, but trust is weakened because the exact npm package/publisher is unverified and all message/auth traffic can be redirected to arbitrary servers via server_url. This is not confirmed malware, but it carries medium risk due to external message-sending capability, local token storage, and configurable data flows.
Confidence: 81%Severity: 58%
Audit Metadata