k-skill-setup
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the setup behavior is mostly aligned with its stated purpose, and consent gates reduce abuse risk, but the skill expands trust in two notable ways: transitive installation of the full bundle and default routing of many service requests through the publisher-hosted proxy instead of official APIs. This is not confirmed malware, but it carries medium security risk from supply-chain and data-flow centralization.
Confidence: 85%Severity: 58%
Audit Metadata