cyrus-setup
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated setup purpose broadly matches integration/auth/config tasks, but the skill’s footprint is larger than a simple installer. Key concerns are explicit credential scraping, authenticated browser automation that can change external services, and transitive execution of unseen sub-skills. No direct exfiltration endpoint is visible in this file, so this is not confirmed malware, but it carries medium-high security risk until the referenced sub-skills and any agent-browser install path are reviewed.
Confidence: 78%Severity: 68%
Audit Metadata