iii-engine-config

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core configuration guidance is coherent, but the skill reaches beyond passive config into installing registry-sourced worker binaries and auto-executing them. Same-project Docker references lower concern somewhat, yet undocumented worker provenance, child-process spawning, and unspecified telemetry endpoints make the overall footprint higher-risk than a simple engine-config skill.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:36 PM
Package URL
pkg:socket/skills-sh/iii-hq%2Fskills%2Fiii-engine-config%2F@75d630e869d2759d98e1d868a7dabee42324359e