project-bootstrap
Warn
Audited by Socket on Jul 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core bootstrap behavior is broadly consistent with the stated purpose, but the default instruction to install a third-party repo-local skill via unpinned `npx skills@latest add yikZero/skills` introduces a meaningful transitive supply-chain risk. Aside from that, filesystem writes, validation commands, and framework/package-manager setup are proportionate to a project bootstrap workflow, and there is no direct credential harvesting or overt exfiltration in the provided content.
Confidence: 82%Severity: 66%
Audit Metadata