new-project
Audited by Socket on Sep 20, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill's capabilities broadly match a project scaffolder, and the installs mostly target plausible official developer tooling. However, its footprint is unusually expansive and depends on many unpinned third-party installers and templates, creating meaningful supply-chain risk. No clear credential theft, covert behavior, or exfiltration flow is present in the provided skill text.
No clear malicious or supply-chain attack behavior is present in the shown fragment. The code is a legitimate project scaffolder, but it generates payment and authentication code with important security weaknesses. Stripe checkout inputs require server-side validation and controlled prices/redirects; webhook signature verification should be mandatory outside an explicitly isolated development mode; Razorpay order IDs must come from the provider and payment status must be verified; and all interpolated scaffold values require context-specific escaping. The fragment alone does not indicate data exfiltration or malware.