sdd-init

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose of project initialization, but the footprint is somewhat broader than necessary: it scans multiple user-level skill directories and persists project context plus a skill registry to an unspecified Engram backend. No direct malware indicators, credential harvesting, remote installer abuse, or obvious malicious data routing are present in the provided text, but the external persistence path and broad local discovery make it medium risk rather than benign.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:00 AM
Package URL
pkg:socket/skills-sh/gentleman-programming%2Fsdd-agent-team%2Fsdd-init%2F@385a272f294cee36614896a631ebf8030e3e8435