setup

Fail

Audited by Socket on Mar 21, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible behavior mostly matches a project-setup skill, but its core purpose is to generate and facilitate installation of additional skills from unseen reference-driven commands. Because the downstream install scope is not auditable in this fragment, the transitive trust and script-execution risk make it more than benign, though there is no clear evidence of credential theft or overtly malicious behavior.

Confidence: 87%Severity: 63%
Obfuscated FileHIGH
references/DECISION_MATRIX.md

This decision matrix is not directly malicious, but it materially increases supply-chain risk if executed as-is. The combination of many third-party packages, frequent global installs, and unpinned 'latest' tags constitutes a moderate security risk: running these commands can lead to arbitrary code execution on developer machines if any referenced package (or its 'latest' release) is compromised or malicious. Recommended actions: do not run blindly — pin versions/checksums, avoid global installs where unnecessary, vet package sources, and run installs in isolated environments or CI with strict allowlists and audit steps.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:14 PM
Package URL
pkg:socket/skills-sh/kalshamsi%2Fpower-engineer-skills%2Fsetup%2F@af7c06d66af0ede65f1d3f2eddd9559f814158a4