configure-ecc
Fail
Audited by Socket on Feb 27, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The provided ECC configuration/install skill is functionally coherent with its stated purpose as an interactive installer. It uses normal installation patterns (git clone, directory creation, cp operations, verification steps) and avoids hardcoded secrets or unintended data flows. Security risks are low to moderate due to lack of integrity verification for the cloned repository; adding content integrity checks and preflight validations would strengthen security without changing the core function.
Confidence: 95%Severity: 90%
Audit Metadata