project-init-orchestrator

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's behavior broadly matches its purpose as a project setup orchestrator, but its core function is to invoke other local skills and downstream package installs whose provenance and exact behavior are not verifiable from this file. Risk is driven mainly by transitive skill trust and unversioned local script execution, not by credential theft or data exfiltration.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/shipshitdev%2Flibrary%2Fproject-init-orchestrator%2F@353a9f617f2c8e0195ffda45ff7bce3689ab3bad