cofounder-computer-setup

Warn

Audited by Socket on Aug 30, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/install.sh

No direct backdoor/exfiltration/credential theft is evident in this Bash fragment. However, the installer executes remote scripts (curl|bash and curl|sh) and uses eval for Homebrew shell env, which are high-impact supply-chain execution points. More importantly, it injects a session-wide instruction into AGENTS.md that forces the agent’s FIRST action to invoke a specific skill (cofounder-playbook) and to follow it for the entire session—this is a strong agent-behavior hijack/policy injection pattern and should be treated as a potentially malicious supply-chain control risk. Overall: medium confidence of malicious/abusive intent, primarily behavioral rather than system malware.

Confidence: 68%Severity: 65%
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose mostly matches its actions, and Windows steps rely on expected official tooling, but the macOS/Linux remediation path hinges on an unpinned remote curl|bash installer and also installs additional cofounder skills. This is a coherent dev-setup skill with notable supply-chain and transitive-trust risk, not clear malware.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
Aug 30, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/locaweb%2Fcofounder%2Fcofounder-computer-setup%2F@7d2a5c859589218119470e098acfee931c06490e67e9e540fba5a231784b3852
Security Audit — socket — cofounder-computer-setup