one

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's broad integration purpose matches its capabilities, but it routes credentials and actions through a third-party aggregation layer and enables high-impact autonomous actions across many connected services. The main concern is data-flow and control concentration in One, plus unattended workflows/syncs, not overt malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 5, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/withoneai%2Fcli%2Fone%2F@f422f6fad75115efdc57d619a2b488bde39877dd