eve-bootstrap
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is internally plausible for platform onboarding, and the SSH public-key use is proportionate, but the install trust is not: the referenced `@anthropic/eve-cli` and Eve domains/commands could not be verified against public Anthropic tooling, while the skill asks users to install that CLI globally and use it for authentication and token handling. This is more consistent with an unverified third-party onboarding flow than a clearly official vendor skill.
Confidence: 88%Severity: 72%
Audit Metadata