octocode-install

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its claimed installer purpose, but it carries medium-high security risk because it runs unpinned third-party npm code, forwards GitHub credentials to Octocode tooling, and installs additional skills into multiple AI clients. No clear evidence of malware or hidden exfiltration is present in the text, but the supply-chain and transitive-trust footprint is larger than a minimal setup helper.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/bgauryy%2Foctocode-mcp%2Foctocode-install%2F@9708008724c2175ae4f63d2175b4212ace2819a9