caveman-setup

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core function is coherent, but it reroutes all LLM traffic and gateway credentials through a Caveman-controlled proxy, and in BYOK mode it forwards provider keys to that proxy. That third-party interception may be the product's purpose, but it materially changes data flow and trust boundaries; combined with an autonomous verification request, this makes the skill medium-high risk rather than benign. The scanner's command-injection hits appear to be documentation/template-literal false positives, not active execution.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/juliusbrussee%2Fcaveman%2Fcaveman-setup%2F@1670043877fff60d9af4eb5db7cbeb2c95140588dda22c03e8a40841dddfc009
Security Audit — socket — caveman-setup