project-setup

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow, but operationally high-impact: it autonomously performs real GitHub account/org actions using the user's existing credentials. No clear malware or exfiltration behavior is present, yet the subagent/autonomous repo administration design makes it a medium-high security risk skill.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:51 AM
Package URL
pkg:socket/skills-sh/dwmkerr%2Fclaude-toolkit%2Fproject-setup%2F@d1d0c3be3d65cb9c2d3716a297a2c945966db84a
Security Audit — socket — project-setup