init-project

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core project-bootstrap behavior is coherent with the stated purpose, but the skill materially expands its footprint by installing and invoking multiple other skills, using unpinned remote executors, and making local/git/Linear state changes. This looks more like a broad automation/orchestration skill than malware, but the transitive trust and supply-chain exposure make it medium-high risk.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/seangjr%2Fproduct-skills%2Finit-project%2F@5a8a26107328cfe796eaafc1c3b88290b6f3c14c