project-setup

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main purpose is coherent with project scaffolding, but it expands into host-level agent/devcontainer management and explicitly installs another skill, creating a transitive trust risk. No clear credential theft or exfiltration is present, so this is not malicious, but the permission and supply-chain footprint is broader than a minimal setup guide.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 4, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/loxosceles%2Fai-dev%2Fproject-setup%2F@fb4a3a1a253a4ce2e3ad9dd6e06dd305e95df361