smart-init

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Smart Init skill spec is largely coherent with an autonomous initialization and knowledge-seeding purpose, including optional external tool installation (Context7 MCP) and local knowledge base generation. However, its emphasis on zero-friction, autonomous operation that writes to project artifacts and seeds Oracle without per-action user confirmation introduces governance and supply-chain risk. This design is suspicious rather than clearly benign, because autonomous actions that modify repository state and install external tooling can be misused if not properly gated. Recommend implementing explicit per-action approvals, clear dry-run modes, visible prompts for significant changes, and strict provenance checks for installed external tooling before enabling full autonomy.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/overlord-z%2Fclaudeshack%2Fsmart-init%2F@d295033ee2032331e36a5f3194fd7a7f18f86640