squad-kickstart
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s project-orchestration behavior is mostly coherent with its stated purpose, and it avoids remote installers, but it forwards locally resolved auth to an unresolved BASE_URL and depends on unseen shared/downstream skills. The main risk is unverified endpoint ownership plus transitive trust, not confirmed malware.
Confidence: 100%Severity: 60%
Audit Metadata