agent-bootstrap

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's local validation/configuration behavior is mostly aligned with its purpose, but it materially exceeds its stated 'no external dependencies' principle by installing remote skills from third-party sources. The main risk is transitive trust and supply-chain exposure through `npx skills add` and raw URL downloads, not confirmed malware or credential theft.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/jwynia%2Fagent-skills%2Fagent-bootstrap%2F@b4b22dc7670e16acc81b6f8133dd7e7671d2720bae4301662046dc1950f752d0
Security Audit — socket — agent-bootstrap