init-monorepo

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall mostly coherent and purpose-aligned for monorepo scaffolding, but the transitive installation of additional agent skills is a material trust expansion and the use of unpinned `@latest` remote execution raises medium supply-chain risk. This is suspicious rather than malicious.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
May 14, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/humanpluslabsoss%2Fskills%2Finit-monorepo%2F@acb2639ea27384bbf5643cef0ba5ba2fae8b9a80