st-execute-blueprint
Warn
Audited by Socket on May 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s repo-automation purpose is coherent, but its trust model is weak. The biggest risks are executing repo-supplied hook instructions, relying on an unspecified secondary skill, and referencing an unverified unpinned `npx strikethroo` initializer. No direct credential theft, exfiltration endpoint, or confirmed malware behavior is shown.
Confidence: 88%Severity: 74%
Audit Metadata