setup-tangram-remote-tool

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The local Tangram setup is broadly coherent, but the optional Connect path materially increases risk: it installs a direct wheel from an unverified domain relationship, forwards authentication to external platform services, and enables sharing a local tool externally. That footprint is plausible for a relay skill, yet the install provenance is not strong enough to treat as benign.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Aug 24, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/mims-harvard%2Ftooluniverse%2Fsetup-tangram-remote-tool%2F@bb67480de784dad5d9ce6b00da316711b5cc5725b89049ff34ff1209cfe558dc
Security Audit — socket — setup-tangram-remote-tool