setup-mimas-template

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core repo-inspection and file-generation behavior is consistent with a scaffolding skill, and there is no clear credential theft or exfiltration. The main concern is trust: the skill’s declared publisher does not match the recommended Mimas source, and it explicitly directs installation of additional skills from that third-party repo, creating a transitive trust chain. Overall this looks more like a coherent but higher-trust workflow than malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/Grade-AI-Labs%2FMimas%2Fsetup-mimas-template%2F@3fd50bcd53e48bf8bd000ac70c7e9c52a5f6f361
Security Audit — socket — setup-mimas-template