kimi

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior matches its stated purpose, and upstream Kimi CLI provenance is reasonably verifiable through official MoonshotAI channels and package registries. However, it adds meaningful risk by relying on the x-cmd wrapper auto-install path and by encouraging YOLO auto-approval, which can let an AI coding agent execute actions with reduced user oversight. No clear credential theft, covert exfiltration, or incompatible capability was shown.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fkimi%2F@563a5f0cbaee58cc5b8cd4afee8cb2bf66376440
Security Audit — socket — kimi