bookstrap-ingest

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall purpose and capabilities mostly align with a research-ingestion skill, and no clear credential-harvesting or third-party proxy behavior is shown. The main risks are trust in unseen local scripts, broad processing of arbitrary web content, and indirect prompt-injection exposure when external content is passed into LLM-based extraction pipelines with Bash available.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/mikkelkrogsholm%2Fbookstrap%2Fbookstrap-ingest%2F@3fc1d0a89990cc4419ff3bdefc0980f13093da2c