superise-bootstrap

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly aligned with its stated Docker bootstrap purpose, but it executes a mutable remote Docker image, handles a first-run password via logs, and mandates handoff to another skill for wallet actions. The data flow is local and the localhost-only binding is a meaningful safeguard, so this looks more like a risky-but-coherent infrastructure/bootstrap skill than outright malicious behavior.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 06:11 AM
Package URL
pkg:socket/skills-sh/appfi5%2Fsuperise-for-agent%2Fsuperise-bootstrap%2F@828558a2da590ab7d541d664824de1054db111d7