setup-engine
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's described workflow is coherent with its stated purpose: it guides engine selection, looks up versions via WebSearch, and updates project documentation accordingly. Data flows and permissions are proportionate to a documentation/configuration automation task, with no credential handling or direct external service access beyond standard web searches. The main caution is to ensure guardrails around version guessing and to implement safe write/rollback safeguards for CLAUDE.md and docs updates. Overall, the skill appears BENIGN with MEDIUM-low security risk due to external web data dependency and documentation-write actions.
Confidence: 98%
Audit Metadata