new-project

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match a project scaffolder, and the installs mostly target plausible official developer tooling. However, its footprint is unusually expansive and depends on many unpinned third-party installers and templates, creating meaningful supply-chain risk. No clear credential theft, covert behavior, or exfiltration flow is present in the provided skill text.

Confidence: 88%Severity: 58%
SecurityMEDIUM
scripts/new-project.ts

No clear malicious or supply-chain attack behavior is present in the shown fragment. The code is a legitimate project scaffolder, but it generates payment and authentication code with important security weaknesses. Stripe checkout inputs require server-side validation and controlled prices/redirects; webhook signature verification should be mandatory outside an explicitly isolated development mode; Razorpay order IDs must come from the provider and payment status must be verified; and all interpolated scaffold values require context-specific escaping. The fragment alone does not indicate data exfiltration or malware.

Confidence: 96%Severity: 70%
Audit Metadata
Analyzed At
Sep 20, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/harshsinghmp%2Fmuse-skills%2Fnew-project%2F@0b2e0d1c461a24cfc44ca1f1960168a049bb0b5c3e23a16d4d15409a8e4dd2ad
Security Audit — socket — new-project