cyrus-setup

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated setup purpose broadly matches integration/auth/config tasks, but the skill’s footprint is larger than a simple installer. Key concerns are explicit credential scraping, authenticated browser automation that can change external services, and transitive execution of unseen sub-skills. No direct exfiltration endpoint is visible in this file, so this is not confirmed malware, but it carries medium-high security risk until the referenced sub-skills and any agent-browser install path are reviewed.

Confidence: 78%Severity: 68%
Audit Metadata
Analyzed At
Mar 21, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/ceedaragents%2Fcyrus%2Fcyrus-setup%2F@2ef02a26b473e912cc2e7369468c6955d1f55489