cmd-setup-phoenix-duskmoon

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Phoenix/DuskMoon setup actions are broadly aligned with the stated purpose, but the skill meaningfully exceeds a simple local setup by instructing transitive use of other skills and allowing autonomous GitHub issue creation. Dependency installs are expected and not inherently malicious, but the combination of transitive trust and public-posting behavior makes this medium risk rather than benign.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:44 AM
Package URL
pkg:socket/skills-sh/gsmlg-dev%2Fcode-agent%2Fcmd-setup-phoenix-duskmoon%2F@192def857ab1dc81cc0f040e335a510c32c8dd1f