k-skill-setup

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the setup behavior is mostly aligned with its stated purpose, and consent gates reduce abuse risk, but the skill expands trust in two notable ways: transitive installation of the full bundle and default routing of many service requests through the publisher-hosted proxy instead of official APIs. This is not confirmed malware, but it carries medium security risk from supply-chain and data-flow centralization.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 09:18 PM
Package URL
pkg:socket/skills-sh/NomaDamas%2Fk-skill%2Fk-skill-setup%2F@0bfad7e1d59f043bb885d2d4d1f4ab4fc2192d0a