wiki-init

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, and the dry-run/explicit-confirmation workflow is a strong benign signal. The main concern is supply-chain trust: on write, it clones and installs QMD from a personal GitHub repo into a managed cache without stating pinning or checksum verification, then wires wrappers/hooks into the project. This is not clearly malicious, but it is broader and riskier than a purely local initializer and deserves medium scrutiny before use.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 11:48 AM
Package URL
pkg:socket/skills-sh/djalmajr%2Fskills%2Fwiki-init%2F@495c03ea4d426dedb08329166c20625ee3b1e919
Security Audit — socket — wiki-init