setup-auditor

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The setup-auditor skill presents a coherent, safety-conscious auditing tool that reads local workspace/configuration to assess credential exposure, sandbox readiness, and least-privilege defaults. It does not appear to introduce additional attack surface (no remote execution, no unreliable downloads, and network access is restricted). The permission model aligns with its stated purpose, and the data flows are consistent with audit-driven read/write of a local report, not external data exfiltration. Overall, the footprint is benign and proportionate to its auditing objective.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:31 PM
Package URL
pkg:socket/skills-sh/useai-pro%2Fopenclaw-skills%2Fsetup-auditor%2F@ea24c08b7a57714fad20d922572202294ac66581