onboardingV2

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core LaunchDarkly onboarding behavior is coherent, and data flow appears aimed at official LaunchDarkly usage, but the skill's main risk is transitive installation of additional remote skills via `npx skills add`. That expands trust beyond the declared skill and grants companion skills broad code-editing and execution ability. No clear credential theft or malicious exfiltration is evident, so this is better classified as medium/high security risk rather than malware.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
May 2, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/launchdarkly%2Fexperimental-agent-skills%2Fonboardingv2%2F@f536135841a66474a9bb4e6bedf1486883cee291