companion-project-creator

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a well-structured, safety-oriented workflow specification for generating and validating runnable companion projects across technologies. It is not itself executing code or exfiltrating data, but its safe deployment depends on trustworthy templates and secure tooling. Recommend maintaining strict template provenance, code reviews of added article-specific extensions, and verifying all external plugins/tools before automation in CI/CD.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:31 AM
Package URL
pkg:socket/skills-sh/mwguerra%2Fclaude-code-plugins%2Fcompanion-project-creator%2F@f3850bf584e7495706915bcfb9c8c86729718f00