spring-boot-project-creator

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is consistent with its stated purpose (bootstrapping Spring Boot projects). It uses official sources (start.spring.io, official Docker images) and writes expected local files (project sources, docker-compose, .env). The primary security concerns are operational: it generates weak default credentials, exposes database ports on the host by default, and includes a development-only JPA setting (ddl-auto=update) that can be dangerous if misapplied to production. There is no evidence of malicious intent or data-exfiltration behavior in the provided content, but the download-execute pattern and default insecure settings justify a moderate security risk rating and caution when using the generated scaffold beyond isolated local development.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:55 PM
Package URL
pkg:socket/skills-sh/giuseppe-trisciuoglio%2Fdeveloper-kit%2Fspring-boot-project-creator%2F@0302c1733fdc8e33f3a7c3e643f1e7e4afd63a18