moshi-best-practices

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches a Moshi host-setup skill, but it carries non-trivial supply-chain and trust-expansion risk: two curl|sh installers, a paired daemon with persistent outbound connectivity, edits to multiple agent configs, and transitive installation of another skill. This looks more like a legitimate but high-trust integration guide than malware, yet the footprint is broader than a simple best-practices document and warrants caution.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:02 AM
Package URL
pkg:socket/skills-sh/rjyo%2Fmoshi-skill%2Fmoshi-best-practices%2F@941c20a5bedbc7c0cc00333e30474853464d0a53a324b999a8447053a39e34dd