temps-platform-setup

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Temps Platform Setup skill provides a coherent workflow for deploying and managing a self-hosted platform, including remote install from a public URL and extensive credential requirements for providers and TLS. However, the combination of a download-execute install pattern from a remote URL, high-privilege credentials (GitHub, Cloudflare, DNS keys), and storage of secrets in CLI config paths creates meaningful supply-chain and credential-exposure risks. While the described functions align with a legitimate platform deployment tool, the installation method and broad credential surface warrant heightened scrutiny and defense-in-depth controls (signed installer, pinning, minimal scope tokens, encryption-at-rest, audit logging, and avoiding plaintext credential exposure in logs or histories). Overall risk is elevated (suspicious-to-high) due to download-execute patterns and credential exposure potential, though not definitively malicious in intent as described.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 09:37 AM
Package URL
pkg:socket/skills-sh/gotempsh%2Ftemps%2Ftemps-platform-setup%2F@20e9a7c8dec1c8cb72fb8e14c77fdab7af012f44