setup-sandcastle

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint is high-risk. It installs and runs a third-party orchestration CLI, forwards an Anthropic API key to it, and enables autonomous issue-driven code changes, commits, and merges; noSandbox() and interactive passthrough further expand impact. Main concerns are supply-chain trust, credential forwarding, and autonomous execution against untrusted issue content.

Confidence: 80%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 09:09 AM
Package URL
pkg:socket/skills-sh/malinskibeniamin%2Fskills%2Fsetup-sandcastle%2F@c13a241a805164f13c9d35b80effb7a599aab7ef
Security Audit — socket — setup-sandcastle