bootstrap

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill grants an AI agent broad authority to clone arbitrary repos, run repo-native installs, and execute health checks influenced by untrusted external content. Install sources are mostly legitimate and there is no clear credential harvesting or exfiltration path, but the combination of arbitrary-repo bootstrap, tool installation, and command execution creates medium-high operational risk for an agent skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 12, 2026, 01:17 PM
Package URL
pkg:socket/skills-sh/jscraik%2FAgent-Skills%2Fbootstrap%2F@1b47695516b4b55b598c9089c6f6dfdba44127be
Security Audit — socket — bootstrap