init-app-stack

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main scaffolding behavior is broadly consistent with the skill’s purpose and uses mostly official developer tooling, so this is not malware-like. However, the skill also instructs transitive installation of third-party marketplace skills/plugins unrelated to simple app initialization, including an autonomous research skill, which makes the overall footprint broader than necessary and raises trust risk.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/bmsuisse%2Fskills%2Finit-app-stack%2F@0989e3ec26f953356a6583517670991cb08c5d4a