groove-admin-install

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill outline is coherent with its stated purpose: it orchestrates a multi-step bootstrap to install backends and companion skills, while preparing session scaffolding and reporting. The most notable security considerations stem from the transitive installation of external skills via npx from GitHub, which introduces supply-chain risk and trust concerns. Overall, the footprint is proportionate to the described administrative bootstrap task, with moderate risk due to external dependency pulls and filesystem writes, but no credential exposure or data exfiltration detected in the described steps.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/andreadellacorte%2Fgroove%2Fgroove-admin-install%2F@519b8253999251ce09676c2b45569d41a1495fb2