onboard

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose fits project onboarding, but the skill's real footprint depends on executing and trusting an unspecified local `ai-toolkit` plus symlinking in additional skills and agents. There is no direct evidence of malware or credential theft in the provided text, but the unverifiable installer provenance and transitive skill installation make the setup high-risk for an AI agent environment.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Jul 7, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/softspark%2Fai-toolkit%2Fonboard%2F@eb27db1be9cd1a80c118194ba60ffaed3dcfb401af2e95802cb0faae7b075ce3
Security Audit — socket — onboard