setup-mimas-template
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core repo-inspection and file-generation behavior is consistent with a scaffolding skill, and there is no clear credential theft or exfiltration. The main concern is trust: the skill’s declared publisher does not match the recommended Mimas source, and it explicitly directs installation of additional skills from that third-party repo, creating a transitive trust chain. Overall this looks more like a coherent but higher-trust workflow than malware.
Confidence: 100%Severity: 60%
Audit Metadata