agentic-os-init

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core behavior is mostly coherent with a local scaffolding skill, and there is no clear credential harvesting or exfiltration path. The main concern is the explicit instruction to install another skill via `npx skills add`, which creates a transitive trust chain beyond simple initialization; combined with Bash/write access and optional global file modification, this makes the skill medium risk rather than benign.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 21, 2026, 12:16 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fagentic-os-init%2F@f95f5c53497d0f554cbbe1b9486a95092574bc73