endor-setup

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill exhibits coherent alignment with its stated aim of automating endorctl setup and scanning in non-interactive environments. However, the footprint introduces substantial security concerns: unverifiable binary installation from a remote API, potential credential exposure via env vars/config, and complex multi-tenant authentication flows that can leak prompts or tokens in non-interactive contexts. Overall, the risk is elevated due to supply-chain and credential exposure patterns, leading to a Suspicious classification with high precaution. Recommendation: constrain to verifiable package sources, implement robust checksum/signature verification, minimize credential exposure, and formally separate non-interactive automation from browser-based authentication flows; add explicit audit logs and secure handling for credentials.

Confidence: 98%Severity: 82%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:12 AM
Package URL
pkg:socket/skills-sh/endorlabs%2Fai-plugins%2Fendor-setup%2F@8c2ead18525e1aa148b693c853737d67accae002