agentic-os-init
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core behavior is mostly coherent with a local scaffolding skill, and there is no clear credential harvesting or exfiltration path. The main concern is the explicit instruction to install another skill via `npx skills add`, which creates a transitive trust chain beyond simple initialization; combined with Bash/write access and optional global file modification, this makes the skill medium risk rather than benign.
Confidence: 84%Severity: 57%
Audit Metadata