domain-init
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Domain Registry Initializer is internally coherent with its stated purpose: it scans libraries, gathers metadata, and updates CLAUDE.md accordingly, with an optional auto-load narrative. No credentials, network calls, or remote code execution are involved. Security risk is low (benign) given local, deterministic file I/O and absence of external dependencies or data exfiltration. Minor risks include potential registry content inaccuracies due to missing metadata or README files and the lack of an explicit dry-run mode, but these are functional concerns rather than security concerns.
Confidence: 98%
Audit Metadata