avalanche-demo-init

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/init_project.py

No direct malicious or obfuscated behavior is evident in this module. However, it performs high-impact supply-chain operations (git clone + uv sync + PATH-resolved npx/pnpx/bunx skills install) and then imports/executes a generated Python workflow during verification. The security posture therefore depends heavily on the integrity of upstream repositories, installed dependencies/skills, and the host’s toolchain binaries available on PATH.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Jul 28, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/Trampoline-AI%2Favalanche%2Favalanche-demo-init%2F@931b35408b8a016a369ee17cda0c677ea5f28bcb79ac454753a5cb53677768a1
Security Audit — socket — avalanche-demo-init