homelab-setup

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it asks the agent to collect many sensitive credentials in chat and store them in a shared local `.env`, while also invoking an unseen local script. There is no clear exfiltration or malicious endpoint in this excerpt, so this is not confirmed malware, but the credential concentration and incomplete trust chain create meaningful risk.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Apr 19, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/jmagar%2Fclaude-homelab%2Fhomelab-setup%2F@75d84c176d50e95d2aee7515841a42dd631c2d83
Security Audit — socket — homelab-setup