init-project
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill’s core dependency is an unverifiable `foyer` CLI with no publicly confirmed publisher, install source, or release integrity evidence. The instructions are otherwise scoped and include confirmation gates, so this is not confirmed malware, but it is high supply-chain risk.
Confidence: 85%Severity: 78%
Audit Metadata