yeelight-interactive-light-experiences
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core loopback/light-control design is mostly aligned with the stated purpose and uses an official same-org runtime, but the skill allows staff-entered provider credentials to be sent to any OpenAI-compatible base URL and depends on an external CLI resolved from local PATH/env. That makes the data-flow and execution trust broader than a tightly scoped local exhibition skill, though not clearly malicious.
Confidence: 84%Severity: 58%
Audit Metadata