swain-init

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core onboarding behavior is mostly coherent and locally scoped, but risk is elevated by supply-chain exposure (official `curl|sh`, transitive pre-commit hook repos) and especially by installing a separate third-party skill via `npx skills add obra/superpowers`. No clear credential theft or exfiltration is present, so this is not malicious, but it is a medium-risk onboarding skill.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 15, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/cristoslc%2Fswain%2Fswain-init%2F@ada2c1b03104c51a18ea7fed9914c929f5ac65c7