meegle-cli
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s operational scope mostly matches a Meegle project-management CLI, but its install trust is not coherent with the public upstream ecosystem: it directs users to an unverified package `@tingwillforever/meegle-cli` instead of the documented official `@lark-project/meegle`. Combined with broad authenticated write/deploy capabilities and private remote MCP routing, this creates high security risk without clear evidence of outright malware.
Confidence: 88%Severity: 84%
Audit Metadata