sim-studio

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent for local workflow orchestration, and most data flows stay on localhost, but it asks the agent to access local secret files and forward an API key through an unpinned third-party CLI (`mcp-remote`) not maintained by the same publisher. This is not confirmed malware, but the install-and-credential-forwarding pattern makes the skill medium/high risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:11 PM
Package URL
pkg:socket/skills-sh/kmshihab7878%2Fclaude-code-setup%2Fsim-studio%2F@ccce6ccbbfe70f7ca91161ecf95dd0aa56b2c65d
Security Audit — socket — sim-studio