project-onboard
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core onboarding, local file reads, git diffing, and context generation are proportionate to the stated purpose and the `.config` findings look benign. The main risk is transitive trust: the skill encourages installing additional skills through a broad-source CLI, which extends the agent's permissions beyond onboarding and introduces supply-chain exposure.
Confidence: 87%Severity: 58%
Audit Metadata