onboard
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose fits project onboarding, but the skill's real footprint depends on executing and trusting an unspecified local `ai-toolkit` plus symlinking in additional skills and agents. There is no direct evidence of malware or credential theft in the provided text, but the unverifiable installer provenance and transitive skill installation make the setup high-risk for an AI agent environment.
Confidence: 85%Severity: 72%
Audit Metadata