full-stack-bootstrap

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The bootstrap workflow is coherent and aligned with its purpose, but it presents notable security gaps: lack of integrity verification for the external ML model, potential exposure of the Bot token in logs or history, and initial permissive handling of secrets. To harden, add checksum/signature verification for the HuggingFace asset, pin dependency versions, enforce strict logging policies that redact tokens, and implement explicit per-action confirmations and least-privilege secret storage with automatic cleanup where feasible.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Ffull-stack-bootstrap%2F@87926512a3c67fe62889c2fe4227f92c31f70dfa