ce-setup

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches its setup/troubleshooting behavior, but it crosses into medium-risk territory by executing install commands sourced from a local diagnostic script and by installing another agent skill transitively. The data flow is mostly local and user-approved, with no clear credential harvesting or exfiltration, so this is not confirmed malware; the main concern is install-trust and transitive skill installation.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
May 2, 2026, 11:15 AM
Package URL
pkg:socket/skills-sh/EveryInc%2Fcompound-engineering-plugin%2Fce-setup%2F@399bc8c7d753d8d12bd43651015c1f0f04f59acc