setup

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main setup/check/install behavior is largely coherent for a developer tooling skill and uses expected package managers, but risk increases because installation is delegated to an unseen helper script, the skill supports unattended installs via flags, includes self-modification/reflection instructions beyond setup scope, and directs the agent to install another skill (`/itp:hooks`). No clear credential theft or exfiltration is present, so this is not malicious, but it is broader and riskier than a minimal setup skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:52 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fsetup%2F@9e4423c192606ef090dec47899a8c8c2e9fc8224