setup

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The setup purpose matches installing skills, but it does so by cloning mutable third-party GitHub repos, symlinking all skills/scripts/hooks into Claude’s active directories, and optionally executing additional repo code and OAuth flows. Official prerequisites lower risk, but the transitive skill installation and unpinned repo trust make this a medium-high security risk rather than benign.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:19 PM
Package URL
pkg:socket/skills-sh/spm1001%2Fclaude-suite%2Fsetup%2F@a3a726f33832f4da47f30e70c1977f41436831bd