os-eval-lab-setup

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it has elevated risk because it installs additional skills transitively, executes broad shell commands on user-controlled paths, and pushes to a remote GitHub repo. This is not clearly malicious, yet its execution footprint is larger than a simple repo bootstrapper and deserves review before use.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fos-eval-lab-setup%2F@8d3c5d276806cb0c81c5ec5cddd996863b113c02