fdk-setup

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
.cursor/commands/fdk-install.md

No explicit malicious code is visible in this fragment; however, it unconditionally triggers a shell-executed task whose effective command payload is delegated to an external relative template (`../SKILL.md`). This creates a meaningful supply-chain risk because the actual executed instructions are not auditable here. Inspect `../SKILL.md` (Operation 1) and ensure it contains only expected installation steps with no network exfiltration, credential access, or arbitrary command execution beyond the intended install.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:23 PM
Package URL
pkg:socket/skills-sh/freshworks-developers%2Fmarketplace%2Ffdk-setup%2F@08a6f91eb4ecda28bf7fbfe4e8f4a918f2322fac