aeo-setup

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its core execution path depends on an unpinned, publicly unverified `npx goose-aeo` CLI and forwards multiple API keys to it. That combination makes the install trust and credential-routing footprint disproportionally risky even though the overall workflow aligns with AEO setup.

Confidence: 82%Severity: 86%
Audit Metadata
Analyzed At
Mar 26, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Faeo-setup%2F@33417665f5b1e09d1cec72e14c9c4864cc43629e