CLI-Hub Skill for CLI-Anything
PassAudited by VirusTotal on Apr 10, 2026.
Findings (1)
The skill functions as a gateway to a third-party ecosystem, instructing the agent to install external software via 'pip install cli-anything-hub' and subsequent 'cli-hub install' commands. This pattern introduces significant supply chain risks by directing the agent to fetch and execute arbitrary Python packages from a custom registry hosted at clianything.cc. While the stated intent is to provide agent-native interfaces for professional software, the lack of verification for these external packages and the broad execution capabilities they provide constitute a high-risk behavior.
