rust-node-bootstrap

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core scaffolding behavior is mostly consistent with the stated purpose, but the skill relies on installing additional skills from a different org than the stated publisher. That transitive installation pattern and publisher mismatch create a meaningful trust and supply-chain risk, even without direct credential handling or exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/onsager-ai%2Fdev-skills%2Frust-node-bootstrap%2F@c874994ecafbd782fbe638d597e7ca8820d01cd6b206701fa292d4ce948124fd
Security Audit — socket — rust-node-bootstrap