rudder-profiles-setup

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its general behavior, but it relies on cloning and executing a remote setup script that installs more tooling, downloads assets, and rewires editor MCP config. The trust chain is plausible for an official RudderStack setup skill, yet the remote-code execution footprint and broad local changes make it medium risk rather than benign.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Jun 23, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/rudderlabs%2Frudder-agent-skills%2Frudder-profiles-setup%2F@9dbe34ae2f89a8b09c9c348047bd0cf1a4ce37c2f91fe2b23bd2c147c80f6809
Security Audit — socket — rudder-profiles-setup