ai-kickoff

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main DSPy/FastAPI scaffolding behavior is benign and proportionate, with official-registry dependencies and normal provider API usage. However, the embedded instruction to install another skill from a personal GitHub repo is a meaningful transitive-trust risk that does not clearly belong in a simple project-bootstrap skill.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
May 13, 2026, 06:46 PM
Package URL
pkg:socket/skills-sh/lebsral%2Fdspy-programming-not-prompting-lms-skills%2Fai-kickoff%2F@cdfcd78dee75e72ed3825403f9bc31335560b09c