opencli

PassAudited by VirusTotal on Mar 27, 2026.

Findings (1)

The skill bundle provides the agent with broad access to sensitive personal data (DMs, bookmarks, history) and the ability to perform write actions (posting, deleting) across 16 social platforms by reusing the user's Chrome session. SKILL.md includes 'self-iteration' instructions that direct the agent to write YAML configuration files to the local filesystem (~/.opencli/clis/) and use browser_evaluate to explore DOM structures. While these capabilities are aligned with the tool's stated purpose of being a CLI for web services, the combination of extensive account access and local file-writing permissions presents a high-risk profile.