setup

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Medium-risk but not clearly malicious. The skill's scanning and configuration behavior mostly fits its onboarding purpose, but arbitrary webhook telemetry, MCP install guidance, and a mismatch between documented writes and declared tools make it more than a low-risk setup helper.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Fsetup%2F@534716854c263344908bb093d83c7e9d5820747a