rock-cli
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s sandbox-management capabilities are broadly consistent with its purpose, but the installation trust chain is weak. It uses a curl-to-shell installer over HTTP from a same-org but non-publicly-documented path, while public Alibaba ROCK docs point to different install methods. Credential use and file transfer are proportionate to the task, but forwarding API keys and potentially sensitive uploads through a CLI installed this way creates meaningful supply-chain and credential-handling risk.
Confidence: 85%Severity: 72%
Audit Metadata