sprites-dev

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The official Sprite-management capability is coherent, but the skill overreaches by mandating a personal-repo `curl|bash` bootstrap and forwarding a Tailscale auth key into that installer. Combined with broad remote admin powers and SSH agent forwarding, the skill’s actual footprint is materially larger and riskier than its stated management purpose.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 12, 2026, 08:11 PM
Package URL
pkg:socket/skills-sh/kylelundstedt%2Fdotfiles%2Fsprites-dev%2F@1b22c79e8d11cf9badf8a89cec2eb1869b1c93fb