project-onboarding

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill footprint is coherent with its stated purpose of onboarding IDEA projects using internal tooling. Data flows are largely local (filesystem-based) with modular orchestration through dedicated sub-skills, and there are no obvious credential exfiltration or external communication patterns. The main risk is potential command-injection surface if user input can influence the exact commands executed during onboarding, especially around vault handling or dry-run/verbose options. Overall, the skill is BENIGN with MEDIUM Security Risk due to actionable shell/tool invocations and the vault onboarding path requiring careful handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/teslasoft-de%2Fclaude-skills-marketplace%2Fproject-onboarding%2F@5ee41bba59ba5dd12472073d12043fc25734765f