onboard
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is legitimate, but the trust model is weak. Broad repo exploration and exact obedience to a local agent file are coherent with onboarding, yet the unpinned external rp-cli dependency, implied third-party skill installation path, and prompt-injection exposure from untrusted codebase content raise medium risk.
Confidence: 81%Severity: 58%
Audit Metadata