tilebox-cli
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is internally consistent with its stated Tilebox CLI purpose and routes data to Tilebox-branded endpoints, so it does not look intentionally malicious. However, it installs an opaque external CLI via curl|sh and then uses that CLI with an API key, which is a high supply-chain and credential-forwarding risk even with same-org branding.
Confidence: 84%Severity: 84%
Audit Metadata