bookstrap-research

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is largely purpose-aligned for autonomous research, with no strong malware or supply-chain indicators, but it combines autonomous web ingestion of untrusted content with Bash/Write access and local state changes. Plaintext local DB credentials and optional routing through Serper add medium risk, making this a high-risk research automation skill rather than a clearly malicious one.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/mikkelkrogsholm%2Fbookstrap%2Fbookstrap-research%2F@e9d90d34f9f1f879b7ca9e36cc836e13f8a20fe0