skill-support

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill-support description coherently maps to a robust internal support CLI for triage, health checks, and evals. However, the use of a direct install-from-remote-script (curl ... | bash) is a significant supply-chain risk that is not proportionate to the stated security posture. The memory-only secret handling and broker-based secret materialization are advanced controls that are beneficial if implemented with strict lifecycle, logging redaction, and minimal in-memory exposure. The combination of multi-source secret flows, transitive skill auto-linking, and reliance on external broker endpoints elevates risk. Recommendation: replace curl | bash with signed releases or a verified package manager, implement code signing verification, pin install script hashes, enforce least-privilege and strict memory/log protections for secrets, and document explicit data-flow provenance and auditability for broker interactions.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/skillrecordings%2Fsupport%2Fskill-support%2F@d410651ea1fc2746d5ca8cf9d01d0d93890d7117