community-project-publish

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its purpose, but it centralizes project publish/fork traffic through a Starchild gateway using an internal key and imports third-party community code into the workspace. The main risks are intermediary trust, untrusted project ingestion, and possible downstream execution of forked code; there is no strong evidence of outright credential theft or overt malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 11:38 AM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcommunity-project-publish%2F@e77f0ebc6621b3786201f2251f42d88d72c07db3