avalanche-demo-init
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
AnomalyAnomalyscripts/init_project.py
LOWAnomalyLOW
scripts/init_project.py
No direct malicious or obfuscated behavior is evident in this module. However, it performs high-impact supply-chain operations (git clone + uv sync + PATH-resolved npx/pnpx/bunx skills install) and then imports/executes a generated Python workflow during verification. The security posture therefore depends heavily on the integrity of upstream repositories, installed dependencies/skills, and the host’s toolchain binaries available on PATH.
Confidence: 66%Severity: 55%
Audit Metadata