homelab-setup

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it asks the agent to collect many sensitive credentials in chat and store them in a shared local `.env`, while also invoking an unseen local script. There is no clear exfiltration or malicious endpoint in this excerpt, so this is not confirmed malware, but the credential concentration and incomplete trust chain create meaningful risk.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Apr 19, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/jmagar%2Fclaude-homelab%2Fhomelab-setup%2F@75d84c176d50e95d2aee7515841a42dd631c2d83