setup

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a documentation/installation guide for the case.dev CLI and does not itself contain executable code, hardcoded secrets, or direct exfiltration routines. However, it promotes a download-and-execute installer (curl | sh) and documents mechanisms (overridable API base URL, per-call API keys, raw API access) that — if misused or if the installer/CLI is compromised — could be used to harvest credentials or exfiltrate data. The main risks are supply-chain (installer execution) and credential forwarding to untrusted endpoints via --api-url or raw API calls. Recommend: avoid pipe-to-shell installers when possible, verify the install script contents and signatures, restrict file permissions for ~/.config/case/config.json, and validate any --api-url before supplying real API keys. Overall classification: suspicious/vulnerable but not clearly malicious in itself.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 07:59 PM
Package URL
pkg:socket/skills-sh/CaseMark%2Fskills%2Fsetup%2F@62f2969c964ef2498364a59454fb63fccd7b6343