stdx_config

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's described workflow is coherent for a developer aiming to integrate and build against the stdx library across platforms. However, the reliance on unverifiable binaries from a third-party release site without checksums or signatures constitutes a notable supply-chain risk, elevating the overall security risk to a suspicious level. Other aspects (library path configuration, OpenSSL dependency note, and local environment changes) align with the stated purpose but should be supplemented with verified binary distribution (official registries, signed artifacts) and explicit integrity verification steps.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/Kong-Baiming%2Fcangjie-dev%2Fstdx-config%2F@53b860891ca533669e39844775705e9f342af6d8