template-initialization

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core template bootstrap behavior is coherent, but the skill overreaches by adding external skill discovery and automatic Copilot tool installation. The main risk is supply-chain and transitive trust expansion, especially the third-party `specify-extend` package and non-official command path; this is not confirmed malware but is higher-risk than a normal local project initializer.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/pradeepmouli%2Fzod-to-form%2Ftemplate-initialization%2F@64d8be84791f097c68e49f071780c5c22ed686d7