configure-ecc

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The analyzed fragment describes a legitimate ECC installation workflow with interactive prompts and broad content deployment. Primary concerns are supply-chain risk due to unverified external content and the potential for installing unwanted components given the large skill/rule surface. Mitigations include enforcing integrity verification (signed releases or checksums), adopting submodule or artifact registries, and implementing a scoped install manifest to limit installed components. Overall security posture is BENIGN with SUSPICIOUS undertones due to external dependency and lack of explicit integrity checks.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/Mark393295827%2Fhouse-maint-ai%2Fconfigure-ecc%2F@c6f641a062dd84a7fd10c5cc6d1b9f8db65246d6