sync-template

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core sync behavior is coherent, but the skill's footprint goes beyond template synchronization by automatically installing fetched files as project and global Claude skills/commands. Trust is further weakened because content is fetched from a mutable personal GitHub repo by branch name rather than pinned commits or signed releases. No direct credential theft is evident, but the transitive skill installation and global file writes make this higher risk than a normal template-sync skill.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Jun 3, 2026, 04:51 AM
Package URL
pkg:socket/skills-sh/rheinmir%2Fsetup%2Fsync-template%2F@45ba82253e4d88bcbb1794dc7467c88ddec468a4
Security Audit — socket — sync-template