adk-scaffold

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill/documentation is coherent for its stated purpose of scaffolding ADK agents, but it embeds a high-risk download-execute pattern (remote installer via curl|sh) and references an unverifiable CLI installer. This introduces supply-chain risk and potential data/credential exposure if misused by an agent. While the core scaffold guidance is legitimate, the download/install pattern warrants caution and likely elevation to suspicious rather than benign until mitigations (verifiable checksums, official registries, or in-repo installers) are provided.

Confidence: 65%Severity: 75%
Audit Metadata
Analyzed At
Mar 6, 2026, 11:16 PM
Package URL
pkg:socket/skills-sh/eliasecchig%2Fadk-docs%2Fadk-scaffold%2F@b328ec49c31fa2577abf3dcfec97b5721dd2726e