warehouse-init

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior broadly matches schema discovery, but it depends on a sibling local CLI with unverifiable data handling and reads home-directory warehouse config, creating moderate trust and credential-handling risk. No clear exfiltration endpoint or overtly malicious behavior is shown; the main concerns are opaque transitive execution and prompt-injection exposure from scanning untrusted repo content while writing files.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Apr 1, 2026, 04:09 PM
Package URL
pkg:socket/skills-sh/astronomer%2Fagents%2Fwarehouse-init%2F@16f86b438a9f5f78184ff4463a9646097cbf26f3