project-scaffolding

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill fragment is internally consistent with its stated purpose and does not exhibit malicious behavior or credential exposure in its content. It provides templates, post-scaffolding steps, and Harness integration patterns that align with legitimate scaffolding workflows. Security risk is low to moderate, driven by the operational nature of executing local build/test commands, but there is no evidence of data exfiltration, credential harvesting, or remote code execution. Recommend proceeding with standard security reviews (review of any included templates, dependency versions, and CI/CD configurations) before broad distribution.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/lobbi-docs%2Fclaude%2Fproject-scaffolding%2F@d197b3123b1c2ecf84f08c2aa3c638ca3b6ad5f7