solo-setup

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is internally consistent: it reads project metadata and manifests to generate docs/workflow.md and to update CLAUDE.md. There are no explicit malicious behaviors, no external download/execute chains, and no credential requests. The primary security considerations are (1) the allowed-tools list includes Bash which increases the ability to execute arbitrary shell commands if the agent is permitted to use that tool; (2) MCP integrations may call out to external services depending on their implementation, so their endpoints and data handling should be trusted/inspected. Overall the manifest appears benign for its stated purpose but requires safe implementation (limit Bash use to minimal commands, avoid reading unrelated sensitive files, and ensure MCP tools are trusted).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/fortunto2%2Fsolo-factory%2Fsolo-setup%2F@ff8e065afdd84c9807dd755510cbc777ceeec523