skillgrade-setup

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the core workflow depends on installing an unverified external CLI and then forwarding powerful LLM API keys and workspace content to it. No clear malicious endpoint is shown, yet install provenance and credential-routing are not sufficiently established, making this a high supply-chain and credential-forwarding risk.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:23 AM
Package URL
pkg:socket/skills-sh/mgechev%2Fskillgrade%2Fskillgrade-setup%2F@6bb4d8ade00cc53b712ba4c57288db7c7b21d17d