setup-codemap-cli

Fail

Audited by Socket on Feb 13, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is a configuration and installation guide for a CLI tool (Codemap). The instructions and requested actions are generally consistent with the stated purpose. The main risks are operational: (1) installing from third-party Homebrew/Scoop taps increases supply-chain trust requirements and should be verified by the user, and (2) hooks run shell commands that read repository state (git diff/status); if hook outputs are forwarded to remote services by the user's tooling, that could leak sensitive repository information. There is no direct evidence of obfuscation or embedded malware in this document. Treat installation sources and hook output destinations with caution, but the document itself appears benign with moderate operational risk.

Confidence: 80%Severity: 35%
Audit Metadata
Analyzed At
Feb 13, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/glennguilloux%2Fcontext-engineering-kit%2Fsetup-codemap-cli%2F@4d5597947ca4d98818081f8501746daf50b300f8