quiver-bootstrap
Audited by Socket on Jul 31, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: The skill is broadly coherent with its stated Quiver bootstrap purpose and uses mostly standard tools, but it has meaningful security risk because it handles secret material, can perform account-changing GitHub actions, and includes transitive skill installation from arbitrary git URLs. No strong evidence of credential exfiltration or malicious hidden behavior appears in the provided content.
No clear indicators of intentional malware (no backdoor, no exfiltration to arbitrary domains, no eval/Function usage shown). However, the code performs high-privilege key and secret material operations and contains a major security issue: it prints the AGE private key and DOTFILES_KEY to logs/console (printSummary). If logs are retained or visible, this can fully compromise encrypted assets. Network trust behavior via ssh-keyscan also depends on the provided gitHost.