tool-inventory-init

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible skill is mostly coherent for local inventory bootstrapping and does not show explicit credential theft or remote exfiltration, but it relies heavily on transitive internal skills/plugins that are not verifiable from the evidence. The main risk is opaque delegated behavior rather than the local bootstrap step itself.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Ftool-inventory-init%2F@8c09db86e347c6f945a95883bbdaffb77815d5fd