zr-project-setup
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is internally coherent for project setup, but it relies entirely on an unverifiable `probe` CLI that can create/update records and send messages. No direct credential theft or exfiltration is shown, yet the dependency trust gap makes this a high security-risk skill under the required scoring rules.
Confidence: 84%Severity: 78%
Audit Metadata