bookstrap-research-path

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's orchestration purpose is internally coherent, but its real risk comes from undocumented trust boundaries: it invokes another skill to perform web research, does not specify official backends or credential flows, and may ingest untrusted external content into a system with write capabilities. No direct malicious behavior or credential theft is shown in this file, but the transitive dependency and unspecified data flows make it medium risk.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:08 AM
Package URL
pkg:socket/skills-sh/mikkelkrogsholm%2Fbookstrap%2Fbookstrap-research-path%2F@07858f13ff2483938152f1bc83e2a8bb6ca715ed