project-os

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill content is mostly a benign local project-governance scaffold with proportionate file writes and no direct credential or exfiltration behavior. The main risk is the third-party transitive installer path and the skill's explicit autonomous orchestration intent, which expand trust and could enable higher-impact actions in practice even though this snippet does not implement them directly.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 09:44 PM
Package URL
pkg:socket/skills-sh/Peiiii%2Fnextclaw%2Fproject-os%2F@45770f8758460d40c1cc0c3eaa03467e8d4097d3