maestro-setup

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign. The fragment is a well-scoped, interactive onboarding/setup workflow that manages local project context and registry state for Maestro, with explicit user prompts for destructive actions and a clear sequencing of steps. It does not read or transmit sensitive credentials, nor does it perform network communication or data exfiltration. The only noteworthy risk is the potential for accidental data loss during --reset, mitigated by explicit confirmation prompts. Overall, the code fragment aligns with its stated purpose as a project onboarding/setup utility.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/reinamaccredy%2Fmaestro%2Fmaestro-setup%2F@2ecb7b561c10eeef9ef51d5062c929b9ddf27845