arcs-dev-tools
Fail
Audited by Socket on Mar 11, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill footprint roughly matches its stated purpose of ARCS toolchain orchestration, but it relies on unverifiable binaries and repository-distributed scripts for critical steps (toolchain install, burn binary). This creates elevated supply-chain risk and potential for environment impact during installs. In absence of explicit verifiable checksums, signatures, or pinned sources, the skill should be classified as SUSPICIOUS rather than Benign, to reflect the possible risk from third-party or unverifiable components.
Confidence: 62%Severity: 62%
Audit Metadata