onboardingV2

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches LaunchDarkly onboarding, and most data flows point to official LaunchDarkly services and official SDK packages. Risk comes from transitive skill installation via `npx skills add`, especially the less-verifiable `launchdarkly/experimental-agent-skills`, plus automatic credential handling and silent file writes. This looks coherent with its purpose but carries medium supply-chain and delegated-execution risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Jun 3, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/launchdarkly%2Fexperimental-agent-skills%2Fonboardingv2%2F@5c0465604bdc059be3ade9b66d7f82624a942f8d
Security Audit — socket — onboardingV2