init

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill functions as a repository exploration and context-file generator. It does not include network calls, remote downloads, obfuscated payloads, or explicit credential exfiltration. The primary security concerns are operational: it instructs autonomous read access to project files without asking the user, and it performs local deletions when run with --reset. These behaviors are potentially dangerous in hostile or multi-tenant execution environments (an agent with broad repo access could read accidental secrets or remove files). There is no evidence of malware, obfuscated code, or supply-chain download-execute patterns in the provided skill text. Recommended mitigations: require explicit user consent before broad automated exploration, limit the skill's permissions to the necessary repository paths, and ensure it never reads known secret stores or transmits secrets to external services.

Confidence: 76%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/reinamaccredy%2Fmaestro%2Finit%2F@f8a28abb0b07d9526f81bada2cdc76f44a926343