configure

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The analyzed workflow is a benign, well-structured interactive configuration utility for qmd collections. It uses standard tooling, maintains idempotency, and requires explicit user consent for potentially disruptive actions (hook installation, overwriting collections). Security risk is low-to-moderate, primarily due to hooks/config changes rather than data exfiltration or remote code execution. The best-practice recommendation is to ensure users understand hook implications and provide easy reversal steps (e.g., removing hooks, restoring prior .claude/qmd.json).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/aviflombaum%2Fclaude-code-in-avinyc%2Fconfigure%2F@46445b681011cff3b74769072915f4f9cdcc731e