tylle-cli

Warn

Audited by Socket on Jul 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a platform CLI skill, but the trust chain is weak: the core `try` binary could not be independently verified as an official same-org tool, yet it is entrusted with authentication and high-impact administrative operations. Because an unverifiable external CLI receives credentials and can mutate sensitive resources, this skill carries high security risk even without direct evidence of malicious behavior.

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Jul 10, 2026, 10:36 PM
Package URL
pkg:socket/skills-sh/trylle-labs%2Fskills%2Ftylle-cli%2F@83c2b38ca4949ca5651157af11b5407ba92d0c685fcb5982aa96201cfc5b67f6
Security Audit — socket — tylle-cli