rstack-bootstrap
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent in purpose, but its footprint is high-risk. It installs other skills, automates account creation/login, creates API keys, stores credentials in plaintext temp files, configures payout wallets, and schedules autonomous external actions. Data flows mostly target the stated services rather than obvious exfiltration endpoints, so this is not confirmed malware, but it is a high-risk autonomous business/credential-handling skill.
Confidence: 90%Severity: 83%
Audit Metadata