setup-agent
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is coherently designed for its stated purpose of setting up and authenticating a Karma agent. Its data flows are appropriate for a CLI authentication flow, using legitimate API endpoints and standard environment configuration practices. The main security considerations are minimal but include careful handling of API keys in logs or terminal output, and ensuring RC-file writes are opt-in and clearly disclosed to the user. Overall, the footprint is benign and proportionate to its goal, with moderate attention needed for credentials exposure in user-facing messages.
Confidence: 98%
Audit Metadata