init-monorepo
Warn
Audited by Socket on May 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Overall mostly coherent and purpose-aligned for monorepo scaffolding, but the transitive installation of additional agent skills is a material trust expansion and the use of unpinned `@latest` remote execution raises medium supply-chain risk. This is suspicious rather than malicious.
Confidence: 87%Severity: 62%
Audit Metadata