overseer
Audited by Socket on Sep 20, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill’s monitoring behavior broadly matches its stated purpose, but it is a persistent autonomous controller rather than a passive observer. The biggest risks are unattended real-world actions on the user’s workflow, broad command/control over panes, and an unverifiable private helper plus unspecified public fallback infrastructure. No clear credential theft or direct exfiltration is shown, so this is not confirmed malware.
The code appears to implement a legitimate pane supervision tool and contains no clear malware, credential theft, exfiltration, or backdoor behavior. It has a notable filesystem safety flaw because externally derived pane IDs are used in state-file paths without validation, and the shared `/tmp` directory may permit symlink or race attacks. Restrict pane IDs to a safe character set, use a private directory with restrictive permissions, and use safer temporary-file handling before deployment.