lokei
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated purpose and it contains good approval guardrails, so it does not read like credential theft or covert malware. However, the install guidance is inconsistent with the vendor’s own documented package name, and the CLI appears proprietary/closed-source while performing significant networking and trust-store changes; combined with relay-based public exposure, that makes the skill higher-risk than a normal documentation-only workflow skill.
Confidence: 88%Severity: 72%
Audit Metadata