NYC

project-init-orchestrator

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's documented capabilities are broadly coherent with its stated purpose (project orchestration). However, there are suspicious and high-risk operational choices: executing scaffold scripts from ~/.claude/skills/* and copying user agent configuration directories (.claude/, .codex/, .cursor/) into the project are both operations that exceed the minimal needs of a project init tool and can expose sensitive data or allow arbitrary code execution. The skill should require explicit user consent before executing home-hosted scripts, avoid blind copying of agent config directories (or at least warn and offer selective inclusion), and recommend integrity checks or pinned package versions for installs. Overall: not overtly malicious in the description, but the described behavior is potentially dangerous in practice and should be treated with caution.

Confidence: 80%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:28 PM
Package URL
pkg:socket/skills-sh/shipshitdev%2Flibrary%2Fproject-init-orchestrator%2F@353a9f617f2c8e0195ffda45ff7bce3689ab3bad