scio

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup.py

The supplied code is an installer/configuration script rather than clear malware. Its security-sensitive behavior is intentional-looking but high impact: it modifies AI harness configuration, can grant broad MCP permissions, enables network access for Codex, passes selected environment variables to child servers, and can disable approval prompts with --trust. External registration and trust scripts are not included, so their behavior requires separate review. No direct credential theft, exfiltration, persistence, or destructive payload is evident in this fragment. Review generated configurations and avoid --trust unless the Scio server and all referenced scripts are trusted.

Confidence: 93%Severity: 62%
Audit Metadata
Analyzed At
Sep 20, 2026, 02:27 PM
Package URL
pkg:socket/skills-sh/evisoft%2Fscio.md%2Fscio%2F@d6ca57dd4ca0a481186ca6144a44079a63bc43cda5ec09df933cdcad03f2a063
Security Audit — socket — scio