configure-ecc
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities mostly fit its purpose as an ECC installer and verifier, and there is no clear credential theft or exfiltration. However, it installs by cloning a personal GitHub repo into /tmp, modifies local agent files, and instructs users to install an additional external skills repo, creating moderate supply-chain and transitive-trust risk disproportionate to a simple configurator.
Confidence: 90%Severity: 56%
Audit Metadata