init-project

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s core dependency is an unverifiable `foyer` CLI with no publicly confirmed publisher, install source, or release integrity evidence. The instructions are otherwise scoped and include confirmation gates, so this is not confirmed malware, but it is high supply-chain risk.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
May 6, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/songlairui%2Ffoyer-mono%2Finit-project%2F@454a4e6621cf133faaa095022c5af8cb46dd90f9