eve-bootstrap

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s onboarding actions are mostly consistent with its stated purpose, and the npm install path appears proportionate. However, it explicitly redirects the Eve CLI to a custom staging/dev API domain for auth and project operations, which weakens data-flow integrity and makes the trust relationship unclear. Risk is moderate rather than malicious because the capabilities largely fit onboarding and there is no clear credential theft or covert behavior.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/incept5%2Feve-skillpacks%2Feve-bootstrap%2F@3f62c77fd14ddce5b765b65dc9e21dedc8fb35cb