NYC

bootstrap-auto

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document defines a capable and broad bootstrap workflow that can be legitimate, but it lacks explicit trust, provenance, and secret-handling controls. Primary risks are credential exposure (via prompts and storing keys), accidental commit of secrets, remote transmission of repository/artifacts to unspecified endpoints, and execution of untrusted dependencies during 'real' tests. The fragment itself is not an obvious malware sample (no obfuscation, no hard-coded malicious endpoints), but its orchestration model increases supply-chain and data-exfiltration risk unless subagents are constrained to trusted/local implementations, secrets are managed securely, and dependency provenance is enforced.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fbootstrap-auto%2F@47c4c1b9995f8a78f1a5e67a918d180c7569317d