eve-bootstrap

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is internally plausible for platform onboarding, and the SSH public-key use is proportionate, but the install trust is not: the referenced `@anthropic/eve-cli` and Eve domains/commands could not be verified against public Anthropic tooling, while the skill asks users to install that CLI globally and use it for authentication and token handling. This is more consistent with an unverified third-party onboarding flow than a clearly official vendor skill.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 07:51 AM
Package URL
pkg:socket/skills-sh/incept5%2Feve-skillpacks%2Feve-bootstrap%2F@def24f6aa03b10e4c1c38b5b04608a69fe3764068e61f3679ac368cdfb4c4855
Security Audit — socket — eve-bootstrap