scaffold
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core scaffolding guidance is mostly coherent and uses expected tools, but it instructs the agent to install/fetch other skills for wallet and Vercel deployment, and to run an unseen deploy.sh script. The main risk is transitive trust plus autonomous onchain/deployment actions, not clear malware or credential theft in this skill alone.
Confidence: 85%Severity: 64%
Audit Metadata