setup-deploy
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core deploy-detection behavior is legitimate, but the skill’s footprint is much broader than its stated purpose: it pulls in a large local gstack control plane, cross-session logging, telemetry, browser-driving, and local-state reads. I do not see confirmed malware or clear credential exfiltration, and the referenced binaries appear same-org rather than arbitrary third-party payloads, but the scope is disproportionate enough to rate as medium risk.
Confidence: 83%Severity: 56%
Audit Metadata