cli-bridge

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's risky capabilities mostly align with its stated purpose as a CLI/local-machine bridge, but the actual footprint is large: remote installer execution, gateway-mediated auth, optional local shell/file access, and local MCP process spawning. This is not clearly malicious, yet it meaningfully increases attack surface and should be treated as medium risk infrastructure for agent-to-laptop control.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fcli-bridge%2F@f7b8eb73028d20e2e8e732709e09113d56adec33a6bcd9399625aca152765a9f
Security Audit — socket — cli-bridge