yeelight-interactive-light-experiences

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core loopback/light-control design is mostly aligned with the stated purpose and uses an official same-org runtime, but the skill allows staff-entered provider credentials to be sent to any OpenAI-compatible base URL and depends on an external CLI resolved from local PATH/env. That makes the data-flow and execution trust broader than a tightly scoped local exhibition skill, though not clearly malicious.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Sep 2, 2026, 01:34 PM
Package URL
pkg:socket/skills-sh/yeelight%2Fyeelight-smart-home-skills%2Fyeelight-interactive-light-experiences%2F@6564c92720c72193e89f823647dd6cfa608c558be8185506cb776d7bc9247713
Security Audit — socket — yeelight-interactive-light-experiences