skillbox-quickstart
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities are mostly coherent for onboarding and provisioning a skillbox, but it carries meaningful security risk from broad local environment scanning, real infrastructure creation, repo syncing, and a same-org yet unpinned raw GitHub curl|bash installer. No clear evidence of malicious credential harvesting or off-purpose exfiltration was shown.
Confidence: 86%Severity: 58%
Audit Metadata