chief-install

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and file operations are coherent for a framework installer, but it uses a classic remote-code execution path by cloning a GitHub repo and running setup.sh, plus an optional transitive skill install. No clear credential harvesting or off-platform exfiltration is present, so this is not malicious, but it carries meaningful supply-chain risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/thaitype%2Fchief%2Fchief-install%2F@931febd1890a8236e03e4c933895f1aa14244c3c
Security Audit — socket — chief-install