project-index

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Project Index manifest appears benign and aligned with its stated purpose: orchestrating analysis, documentation generation, auditing, and a local dashboard for large codebases. The primary security considerations are the integration surface for Kanban endpoints and the explicit guidance around destructive Git operations, which could become risky if automation ignores prompts. No credential harvesting, external payloads, or hardcoded secrets were detected. Overall, the security posture is moderate; primary risk arises from potential automated misuse of destructive commands and exposure of integration endpoints if misconfigured.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/mkSteady%2FmkSkills%2Fproject-index%2F@7c97174a3b88955138c3abf8fb46e2eebced1a9e