scaffold-project

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the Solana scaffolding purpose broadly matches the repo/tooling actions, but the trust model is stretched by arbitrary telemetry routing through a config-supplied URL and especially by installing other skills from URLs. Core Solana/Anchor commands look legitimate, yet the transitive skill install and mutable supply-chain steps make this higher-risk than a normal framework guide.

Confidence: 85%Severity: 81%
Audit Metadata
Analyzed At
Apr 14, 2026, 03:17 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fsolana-new%2Fscaffold-project%2F@aba0b61966439a084a1cf69394f714837111da63