stably-sdk-setup
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: The core Stably/Playwright setup behavior is mostly coherent and uses official package sources, so this is not malware-like. The main concern is Step 5's transitive installation/loading of another skill's content into multiple agent-instruction files, which expands trust and influence beyond normal SDK setup. Autonomous file edits and installs further raise risk, but credential handling and primary data flows are otherwise proportionate.
Confidence: 89%Severity: 68%
Audit Metadata