cx-init

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This skill/spec is functionally consistent with its stated purpose (initializing a local CX workflow). It does not itself show explicit malicious code or network exfiltration. However, it installs and registers local shell hook scripts and configures automatic permission approval behavior, while offering no concrete provenance or integrity checks for the hook script contents or the 'cx-workflow plugin'. Because hooks run arbitrary shell commands in the repository context and PermissionRequest auto-approval reduces user oversight, this introduces a moderate supply-chain risk. Recommendation: treat as SUSPICIOUS — review the actual hook scripts' contents and ensure any plugin sources are authenticated/signed before running; avoid overly broad auto-approve policies. LLM verification: Functionally the skill is coherent: it legitimately needs to write config and status files, update CLAUDE.md, and register hooks to function. However, the installer gives the agent the ability to execute arbitrary shell scripts placed in the repository and to auto-approve permission requests. Because the hook script contents and the plugin source/integrity checks are not provided, this creates a moderate supply-chain and privilege-escalation risk: an attacker who can modify repository files or s

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:35 PM
Package URL
pkg:socket/skills-sh/m19803261706%2Fcx-workflow%2Fcx-init%2F@d2866f43b134dd07a9e0d09cbc7649ee84c6d143