bookstrap-init

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent for local book-project setup, but its broad Bash permission, execution of an unseen local schema script, and unverifiable delegation to `brd-creator` create meaningful trust and scope concerns. No clear credential exfiltration or malicious data routing is visible in the provided excerpt, so this is better classified as medium-risk/vulnerable rather than malicious.

Confidence: 81%Severity: 52%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/mikkelkrogsholm%2Fbookstrap%2Fbookstrap-init%2F@5c8e7b9d46b7a11f0065dbdaf3128169ebe5bc7e