domain-init

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Domain Registry Initializer is internally coherent with its stated purpose: it scans libraries, gathers metadata, and updates CLAUDE.md accordingly, with an optional auto-load narrative. No credentials, network calls, or remote code execution are involved. Security risk is low (benign) given local, deterministic file I/O and absence of external dependencies or data exfiltration. Minor risks include potential registry content inaccuracies due to missing metadata or README files and the lack of an explicit dry-run mode, but these are functional concerns rather than security concerns.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:10 AM
Package URL
pkg:socket/skills-sh/bogusweb%2Fworkspace-context-skills%2Fdomain-init%2F@a2518620bb5831388b3d9c4f687f5fb669f37526