skillbox-quickstart

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are mostly coherent for onboarding and provisioning a skillbox, but it carries meaningful security risk from broad local environment scanning, real infrastructure creation, repo syncing, and a same-org yet unpinned raw GitHub curl|bash installer. No clear evidence of malicious credential harvesting or off-purpose exfiltration was shown.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/build000r%2Fskills%2Fskillbox-quickstart%2F@a5b643b48a3ac7e8d10cf8edea2188eb33ca9bc2