rch
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly coherent with a remote compilation helper and its SSH-based worker management is proportionate to that purpose, but it enables remote execution/file transfer across a fleet and omits any verifiable install/provenance details for the core `rch` tooling. Main concern is execution trust and expanded access scope, not confirmed malware or credential theft.
Confidence: 81%Severity: 58%
Audit Metadata