latitude-setup

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business purpose is coherent, and the intended data flow to Latitude is plausible, but the install/execution trust is not: the skill relies on a standalone CLI binary distribution path that does not match the official npm-based install docs in the supplied evidence, then forwards a freshly generated API key to that CLI for authenticated operations. It also expands trust transitively to other skills and performs autonomous remote project changes. Main risk is supply-chain and credential-forwarding, not confirmed malicious exfiltration.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Jul 9, 2026, 02:03 AM
Package URL
pkg:socket/skills-sh/latitude-dev%2Fskills%2Flatitude-setup%2F@00d6ceb67a9fc585ff66feb5fc3844abcb86d86c39f1021d06a3c1b1d5cb74ed
Security Audit — socket — latitude-setup