k-skill-setup
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly coherent setup guidance for secret management, with legitimate tool choices and no clear credential-harvesting endpoint. The main risks are transitive skill installation via the skills CLI, optional persistence, and decrypted secret injection into arbitrary commands; these are proportionate to setup but still medium-risk for an AI agent skill.
Confidence: 87%Severity: 62%
Audit Metadata