agent-bootstrap
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the local validation/configuration behavior fits the stated bootstrap purpose, but the remote-skill installation model is disproportionate and internally inconsistent with the stated 'no external dependencies' principle. The main risk is transitive trust and supply-chain exposure through unpinned `npx skills add` and arbitrary raw/git URL installs, not confirmed malware.
Confidence: 89%Severity: 84%
Audit Metadata