bootstrap-skill
What this skill does
Bootstrap an AI workflow system called Trellis in a project. It installs a CLI tool, sets up configuration, and initializes the Trellis system.
github/mindfold-ai - Insecure Dependency - 13.8k stars
Threat analysis
Skill info
pkg:github/mindfold-ai/Trellis@c8e327a?skill=bootstrap-skillAssessments (2)
Insecure Dependency
Insecure Dependency via local-llm-review
install.sh
The script downloads and executes code from an external source (https://raw.githubusercontent.com/mindfoldhq/trellis/main/skills/trellis-bootstrap/install.sh) without verifying its integrity or authenRemote code execution
Remote code execution via anomity-rules model-disputed
install.sh
# curl -sSL https://raw.githubusercontent.com/mindfoldhq/trellis/main/skills/trellis-bootstrap/install.sh | bashBadge
Add the Anomity scan badge for bootstrap-skill to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of bootstrap-skill? Report an issue or request a rescan.




