ai-todo

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its trust model is weak: it depends on an external CLI and custom remote service whose publisher relationship was not verified, reads a raw credential file, and allows server-driven command discovery. This is more consistent with a medium/high-risk third-party integration than a clearly benign, well-scoped skill.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 23, 2026, 01:33 AM
Package URL
pkg:socket/skills-sh/strzhao%2Fai-todo-cli%2Fai-todo%2F@56c0157b95b476d9edea9570b64241cacc663783