squad-kickstart

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s project-orchestration behavior is mostly coherent with its stated purpose, and it avoids remote installers, but it forwards locally resolved auth to an unresolved BASE_URL and depends on unseen shared/downstream skills. The main risk is unverified endpoint ownership plus transitive trust, not confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 11:05 PM
Package URL
pkg:socket/skills-sh/steloit%2Fsquad-skills%2Fsquad-kickstart%2F@71024d085153b3b66d1e631a4d61b14109d7934a3c98e305f189a4b76e829f90
Security Audit — socket — squad-kickstart