base

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most of the skill is benign development guidance, but the credential-management section is materially misaligned with a universal base skill: it instructs reading a centralized personal secrets file, parsing multiple API keys, validating them, and populating project .env files. The automatic /ralph-loop delegation also expands trust scope. No confirmed malware or attacker-controlled exfiltration endpoint is present, but the skill’s secret-handling footprint is disproportionate to its stated purpose.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:32 AM
Package URL
pkg:socket/skills-sh/alinaqi%2Fclaude-bootstrap%2Fbase%2F@2d99b60c38faccabd01ae518aea002275a23ce03