ln-700-project-bootstrap
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's broad project-modification behavior is largely coherent with its stated bootstrap purpose, and the GitHub raw fallback appears same-org rather than an obvious exfiltration path. The main security concern is transitive trust: this orchestrator instructs the agent to invoke multiple other skills with substantial write/exec authority, plus remote reference fetching can feed untrusted instructions into that workflow.
Confidence: 84%Severity: 58%
Audit Metadata