agent-bootstrap

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the local validation/configuration behavior fits the stated bootstrap purpose, but the remote-skill installation model is disproportionate and internally inconsistent with the stated 'no external dependencies' principle. The main risk is transitive trust and supply-chain exposure through unpinned `npx skills add` and arbitrary raw/git URL installs, not confirmed malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:55 AM
Package URL
pkg:socket/skills-sh/jwynia%2Fagent-skills%2Fagent-bootstrap%2F@fd1890b994a7986bd2e981b07cd8ca6a871856ef