sol-luna-setup
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is plausible and most file writes are consistent with agent setup, but the skill expands trust by installing a third-party skill from a personal GitHub repo, optionally using curl|sh for Pi, and forwarding model credentials through multiple CLIs/gateway paths. This looks more like a high-risk bootstrap skill than malware, with the main concerns being transitive trust and supply-chain exposure rather than overt exfiltration.
Confidence: 86%Severity: 74%
Audit Metadata