agent-toolkit-setup

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its basic API and .env behavior, but it forwards credentials to an unconstrained, not publicly verified base URL and then loads remote skill instructions into agent context. That combination is coherent with a registry client, yet the trust boundary is too weak to treat as benign.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 09:05 PM
Package URL
pkg:socket/skills-sh/escapewu%2Fskills%2Fagent-toolkit-setup%2F@02b758d67ae7b5f46bdaf313e6d82adf83ee4415
Security Audit — socket — agent-toolkit-setup