sdd-setup

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main behavior is coherent with repository setup for an issue-driven GitHub workflow, and its GitHub/file operations are proportionate. The key risk is transitive trust: it asks the agent to install `mattpocock/skills` via a third-party `skills` CLI/plugin path, expanding the trust boundary beyond this skill. No credential harvesting, covert exfiltration, pre-execution directives, or unrelated data flows are present.

Confidence: 89%Severity: 62%
SecurityMEDIUM
workflows/sdd-review.yml

No explicit malware is evident in this workflow, but it combines untrusted pull-request content with a secret-bearing AI action, write permissions, OIDC capability, and an unpinned third-party plugin. Restrict execution to trusted contributors or use a safer event/approval design, minimize permissions, avoid exposing secrets to untrusted PRs, and pin actions and plugin dependencies to immutable revisions.

Confidence: 91%Severity: 73%
Audit Metadata
Analyzed At
Sep 24, 2026, 02:29 AM
Package URL
pkg:socket/skills-sh/syn54x%2Fskills%2Fsdd-setup%2F@9af9947732989ac1bf9519c450808ae976708ab9fd07cece3fa8c669cbb97149
Security Audit — socket — sdd-setup