overseer

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s monitoring behavior broadly matches its stated purpose, but it is a persistent autonomous controller rather than a passive observer. The biggest risks are unattended real-world actions on the user’s workflow, broad command/control over panes, and an unverifiable private helper plus unspecified public fallback infrastructure. No clear credential theft or direct exfiltration is shown, so this is not confirmed malware.

Confidence: 87%Severity: 72%
AnomalyLOW
overseer.sh

The code appears to implement a legitimate pane supervision tool and contains no clear malware, credential theft, exfiltration, or backdoor behavior. It has a notable filesystem safety flaw because externally derived pane IDs are used in state-file paths without validation, and the shared `/tmp` directory may permit symlink or race attacks. Restrict pane IDs to a safe character set, use a private directory with restrictive permissions, and use safer temporary-file handling before deployment.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/a-canary%2Farc-skills%2Foverseer%2F@ecb27d0ec3160752a9377954b20ff41db567906970e42ff412297f528288f22e
Security Audit — socket — overseer