init-jean-json
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose and capabilities are largely aligned for repo worktree onboarding, and install trust is relatively normal. The main risk is that it tells an AI agent to read untrusted repo content and then execute repo-derived setup/run commands with shell and write access while secret files may be present in the environment/worktree, creating a meaningful indirect prompt-injection and command-execution risk even without explicit exfiltration behavior.
Confidence: 88%Severity: 64%
Audit Metadata