project-setup
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s main purpose is coherent with project scaffolding, but it expands into host-level agent/devcontainer management and explicitly installs another skill, creating a transitive trust risk. No clear credential theft or exfiltration is present, so this is not malicious, but the permission and supply-chain footprint is broader than a minimal setup guide.
Confidence: 84%Severity: 64%
Audit Metadata