eightctl

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it asks the agent to install and trust a personal third-party CLI, hand over account credentials, and perform real-world device actions through an unofficial API. This is not confirmed malware, but the trust and credential-forwarding footprint is broader than a low-risk utility.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
May 18, 2026, 02:17 AM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Feightctl%2F@32a760dfa2e534724cb39b464880bb5339dd1da8
Security Audit — socket — eightctl