start-from-scratch

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] BENIGN with caveats. The skill/documentation aligns with its stated purpose of guiding project bootstrap. The primary security consideration is how API keys are supplied and stored (command-line arg vs. environment file). This is a standard pattern for CLI onboarding but warrants explicit best-practice guidance (do not commit .env.local, rotate keys, use environment protections). Overall data flow and sources/sinks are proportionate to the described workflow.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:27 PM
Package URL
pkg:socket/skills-sh/tambo-ai%2Ftambo%2Fstart-from-scratch%2F@71597c763b5905517d64a383a8c755c07fe2ee8c