st-execute-blueprint

Warn

Audited by Socket on May 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s repo-automation purpose is coherent, but its trust model is weak. The biggest risks are executing repo-supplied hook instructions, relying on an unspecified secondary skill, and referencing an unverified unpinned `npx strikethroo` initializer. No direct credential theft, exfiltration endpoint, or confirmed malware behavior is shown.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 28, 2026, 08:55 PM
Package URL
pkg:socket/skills-sh/e0ipso%2Fstrikethroo%2Fst-execute-blueprint%2F@0bddec4ed9915daec3c53ca50e123fb8e7ca7030
Security Audit — socket — st-execute-blueprint