asd-ste100

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is benign and the data flow is mostly local, with no credential harvesting or third-party API routing. The main risk is that the skill directs the agent to execute an unverifiable local linter script that was not included or provenance-linked, which is disproportionate to a pure style guide and triggers a high supply-chain concern even without evidence of malicious intent.

Confidence: 87%Severity: 72%
AnomalyLOW
install.py

The fragment is a configuration installer rather than overt malware. It intentionally establishes persistent Claude Code lifecycle hooks and symlinks package content into ~/.claude, which is security-sensitive because the omitted hook scripts will run automatically and can influence prompt and tool processing. No direct credential theft, network exfiltration, obfuscation, or destructive behavior is shown. Review the four referenced hook scripts before installation, especially ste-inject.py and ste-pregate.py.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/woosal1337%2Fblog%2Fasd-ste100%2F@d19b8d6340697a8224409f0ceb6321d89eca4b08dee05640ffc2442794cc99b6
Security Audit — socket — asd-ste100