tilebox-cli

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated Tilebox CLI purpose and routes data to Tilebox-branded endpoints, so it does not look intentionally malicious. However, it installs an opaque external CLI via curl|sh and then uses that CLI with an API key, which is a high supply-chain and credential-forwarding risk even with same-org branding.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:47 PM
Package URL
pkg:socket/skills-sh/tilebox%2Fskills%2Ftilebox-cli%2F@3fd7c2c1de22823577e9fd43c7b2884c7abb7bc57d035e8706826e377136f381
Security Audit — socket — tilebox-cli