k-skill-setup

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent setup guidance for secret management, with legitimate tool choices and no clear credential-harvesting endpoint. The main risks are transitive skill installation via the skills CLI, optional persistence, and decrypted secret injection into arbitrary commands; these are proportionate to setup but still medium-risk for an AI agent skill.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/NomaDamas%2Fk-skill%2Fk-skill-setup%2F@7436cf4347829ff9947189b88b0c20bbc4671356