agent-onboarding

Warn

Audited by Socket on Jun 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's broad operational scope is mostly consistent with its stated onboarding purpose, but it is disproportionately powerful for a tutorial: it can auto-install dependencies, process sensitive real-world data, interact with external services, and potentially chain into other skills. No clear malicious exfiltration or covert behavior is shown, yet the combination of broad tool permissions, unspecified package installs, and optional account-linked workflows makes this a medium-high security risk rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 8, 2026, 01:42 PM
Package URL
pkg:socket/skills-sh/kaijie0074-art%2Fagent-onboarding-skill%2Fagent-onboarding%2F@2b366c4092e238e13742e369c9f3f1daaaa6c9d9
Security Audit — socket — agent-onboarding