arcs-dev-tools

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill footprint roughly matches its stated purpose of ARCS toolchain orchestration, but it relies on unverifiable binaries and repository-distributed scripts for critical steps (toolchain install, burn binary). This creates elevated supply-chain risk and potential for environment impact during installs. In absence of explicit verifiable checksums, signatures, or pinned sources, the skill should be classified as SUSPICIOUS rather than Benign, to reflect the possible risk from third-party or unverifiable components.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Mar 11, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/LISTENAI%2Fskills%2Farcs-dev-tools%2F@53922db1951caffac9615555103c1c0d795bda5b