studio-startup

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core workflow is mostly coherent for an MVP orchestration skill, and there is no direct credential theft or exfiltration pattern. Risk comes from broad delegation to unverified external skills/plugins and transitive installation guidance, which expands trust beyond the skill itself without clear provenance controls.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:04 AM
Package URL
pkg:socket/skills-sh/kriscard%2Fkriscard-claude-plugins%2Fstudio-startup%2F@6e3b10b698f012b031f8b740fd7e3f45683b39c3