setup-company

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it gathers user-provided company/product information and writes a local company-profile.md used by other demo-prep skills. There are no evident supply-chain, credential harvesting, or data exfiltration patterns. The data flow is strictly source (user input) -> sink (local file). The overall risk is low to moderate and proportionate to the task.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 01:34 PM
Package URL
pkg:socket/skills-sh/tough-tongue%2Fdemo-prep-skills%2Fsetup-company%2F@7aa25b5b1e9e6b349be965069f5e2560db049971