stably-sdk-setup

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The core Stably/Playwright setup behavior is mostly coherent and uses official package sources, so this is not malware-like. The main concern is Step 5's transitive installation/loading of another skill's content into multiple agent-instruction files, which expands trust and influence beyond normal SDK setup. Autonomous file edits and installs further raise risk, but credential handling and primary data flows are otherwise proportionate.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/stablyai%2Fagent-skills%2Fstably-sdk-setup%2F@1fb32cadfbc0c231bf99e25e982b7e49cfea3c69