setup

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's direct behavior is mostly benign local markdown editing and repo analysis, but it steers future operations through unverifiable 'skrrt'/'ship' skills, creating a transitive trust risk disproportionate to a simple setup helper. No confirmed malware or direct exfiltration is present in this skill alone.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:15 AM
Package URL
pkg:socket/skills-sh/skrrt-sh%2Fskills%2Fsetup%2F@3aa23c2b22b1d6cdc57d7029cd847aba033ff5bb