auth-setup

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (setting up Goldsky CLI authentication and project configuration) is not well-aligned with its actual footprint. It relies on downloading and executing an external script from a non-official domain, and it requires users to paste API tokens into chat, creating clear credential and supply-chain risks. While the intent is legitimate for assisting setup, the installation method and token handling introduce high risk that is disproportionate to a typical setup helper. Therefore, the skill should be treated as SUSPICIOUS to HIGH-RISK, with mandatory remediation to switch installation to a verifiable, signed package registry, and to implement secure, in-app token input (not chat-pasted tokens) and safer credential handling.

Confidence: 98%Severity: 85%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/goldsky-io%2Fgoldsky-agent%2Fauth-setup%2F@bce8ae3d29309ce20a46c8df03deb9f29cd0dd38