code-env-setup

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose and local file access are mostly coherent for a Claude Code setup wizard, and user confirmation reduces abuse risk. The main concerns are mutable remote guidance fetched at runtime from a personal GitHub repo and transitive trust from installing MCP servers, which make the skill higher risk than a purely local documentation/setup helper.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 26, 2026, 10:55 AM
Package URL
pkg:socket/skills-sh/joaquimscosta%2Farkhe-claude-plugins%2Fcode-env-setup%2F@9069f37a672be5e2cb0d69d5c8541dc10c6b0681