project-onboard

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core onboarding behavior is coherent and mostly benign, with appropriately scoped repo inspection and local file generation. The main risk comes from optional transitive skill installation through the official `skills` CLI: same-org provenance lowers supply-chain concern, but installing additional third-party skills materially expands trust and permissions, so overall risk is medium rather than low.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:38 AM
Package URL
pkg:socket/skills-sh/nixxel-company-limited%2Fnixxel-skills%2Fproject-onboard%2F@b167c567801309699cb74f2c6da058c8892ca436