configure-ecc
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's behavior mostly matches its stated purpose as an ECC installer, and I found no credential harvesting or exfiltration. However, it clones unpinned content from a personal GitHub repo and installs many downstream skills into active agent directories, so the transitive trust and mutable-source supply-chain risk make it higher than benign.
Confidence: 87%Severity: 58%
Audit Metadata