onboarding

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with legitimate LaunchDarkly onboarding and uses mostly official LaunchDarkly endpoints and normal SDK/package-manager installs, so it is not fundamentally malicious. However, its footprint is fairly expansive for onboarding: it installs transitive skills through a third-party CLI, may fetch and write real credentials, edits agent MCP config, starts local services, and emphasizes quiet execution. Those compounding trust and autonomy signals make it higher risk than a simple documentation or setup skill, though not incompatible with its stated purpose.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:45 AM
Package URL
pkg:socket/skills-sh/launchdarkly%2Fai-tooling%2Fonboarding%2F@eb17092bb346383747ef168d8e145096d9bbaf8dd724a7caf45a862ce55c1e83
Security Audit — socket — onboarding