meegle-cli

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s operational scope mostly matches a Meegle project-management CLI, but its install trust is not coherent with the public upstream ecosystem: it directs users to an unverified package `@tingwillforever/meegle-cli` instead of the documented official `@lark-project/meegle`. Combined with broad authenticated write/deploy capabilities and private remote MCP routing, this creates high security risk without clear evidence of outright malware.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:44 AM
Package URL
pkg:socket/skills-sh/tingwillforever%2Fmeegle-skills%2Fmeegle-cli%2F@bebf568c04a0743bb1fb95c0de67303e94431b4e13f289e6c7790792d473319c
Security Audit — socket — meegle-cli