scaffold

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align for scaffolding, and I see no direct credential harvesting or outbound exfiltration. However, it requires executing an external hoyeon-cli binary whose provenance is not verified in the provided evidence; that alone makes the install/execution trust high risk under the mandated scoring rules. The rest of the behavior is largely coherent and locally scoped.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fscaffold%2F@2ba86c7f2e31c1dc80ff7ebc5682e097b3d5d5a1