x-cmd
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated purpose matches its behavior as a bootstrapper, but it is high-trust infrastructure rather than a narrow utility. The main concerns are official-but-risky remote installation, broad execution surface via third-party tool installs, and transitive skill loading through `x skill`. No clear credential theft or covert exfiltration is shown in the provided content.
Confidence: 83%Severity: 71%
Audit Metadata