Project Scaffolding

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s main purpose is coherent, but its trust model is weak: it instructs the agent to locate, copy, and persistently execute an unverified local shell script from `$CLAUDE_PLUGIN_DIR` or an arbitrary match under `~/.claude`. That makes this better classified as suspicious rather than benign, driven by local supply-chain and persistent auto-execution risk rather than clear malware or exfiltration.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 3, 2026, 02:12 PM
Package URL
pkg:socket/skills-sh/hedera-dev%2Fhedera-skills%2Fproject-scaffolding%2F@e8f50d68b15d82406a7ee822a67a5d134ded9485
Security Audit — socket — Project Scaffolding