quiver-bootstrap

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated Quiver bootstrap purpose and uses mostly standard tools, but it has meaningful security risk because it handles secret material, can perform account-changing GitHub actions, and includes transitive skill installation from arbitrary git URLs. No strong evidence of credential exfiltration or malicious hidden behavior appears in the provided content.

Confidence: 88%Severity: 61%
SecurityMEDIUM
scripts/build-stack.mjs

No clear indicators of intentional malware (no backdoor, no exfiltration to arbitrary domains, no eval/Function usage shown). However, the code performs high-privilege key and secret material operations and contains a major security issue: it prints the AGE private key and DOTFILES_KEY to logs/console (printSummary). If logs are retained or visible, this can fully compromise encrypted assets. Network trust behavior via ssh-keyscan also depends on the provided gitHost.

Confidence: 75%Severity: 70%
Audit Metadata
Analyzed At
Jul 31, 2026, 10:32 PM
Package URL
pkg:socket/skills-sh/jimweller%2Fclanker-skills%2Fquiver-bootstrap%2F@5077badeed1144514c4551d7ab018a2aee67363663a654884082315f80894ecb
Security Audit — socket — quiver-bootstrap