aeo-setup
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but its core execution path depends on an unpinned, publicly unverified `npx goose-aeo` CLI and forwards multiple API keys to it. That combination makes the install trust and credential-routing footprint disproportionally risky even though the overall workflow aligns with AEO setup.
Confidence: 82%Severity: 86%
Audit Metadata