freshworks-fdk-setup-skill

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (managing FDK lifecycle) is coherent with the commands it describes, but its operational design raises significant supply-chain and autonomy risks. Key concerns: it mandates automated, immediate spawning of shell subagents that run download-and-execute commands (curl | bash) and install remote tarballs from a CDN without user approval or package verification. It also modifies user shell configuration files and encourages privilege escalation when installation errors occur. These patterns make the skill SUSPICIOUS for automated execution in environments where users or operators expect reviewed, consented changes. If used, require human confirmation, limit subagent privileges, avoid curl|bash, prefer pinned, signed releases, and present diffs of any shell-profile changes before applying them.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:44 AM
Package URL
pkg:socket/skills-sh/freshworks-developers%2Ffreshworks-platform3%2Ffreshworks-fdk-setup-skill%2F@5b5733da769cfe4cd1a681a27d6a576bc230747a