chief-install
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and file operations are coherent for a framework installer, but it uses a classic remote-code execution path by cloning a GitHub repo and running setup.sh, plus an optional transitive skill install. No clear credential harvesting or off-platform exfiltration is present, so this is not malicious, but it carries meaningful supply-chain risk.
Confidence: 84%Severity: 58%
Audit Metadata