base-app-setup

Fail

Audited by Socket on Feb 22, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The fragment is a non-executable setup manifest that delegates real, actionable steps to remote recipe endpoints. The content as provided is not directly malicious but presents a supply-chain risk because it encourages fetching external instructions without integrity checks. The highest-risk scenarios arise when users or automation blindly execute fetched content or follow recipes that instruct uploading secrets or connecting to third-party managed services. Treat the referenced URLs as untrusted until each recipe is retrieved and audited; prefer pinned content, integrity checks, and secure secret handling.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 22, 2026, 02:55 AM
Package URL
pkg:socket/skills-sh/andrelandgraf%2Ffullstackrecipes%2Fbase-app-setup%2F@eaf86ad65de27520c96275ecac14b40a21499cfe