latitude-setup
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The business purpose is coherent, and the intended data flow to Latitude is plausible, but the install/execution trust is not: the skill relies on a standalone CLI binary distribution path that does not match the official npm-based install docs in the supplied evidence, then forwards a freshly generated API key to that CLI for authenticated operations. It also expands trust transitively to other skills and performs autonomous remote project changes. Main risk is supply-chain and credential-forwarding, not confirmed malicious exfiltration.
Confidence: 84%Severity: 82%
Audit Metadata