skillopt-lite

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main capabilities fit its stated optimization purpose, but it accesses broad local transcripts, routes evaluation through an opaque CLI/proxy, and forwards a real API key into unverified local sandbox tooling. Not clearly malicious, yet the install/execution trust and data-flow transparency are weaker than ideal for a skill that reprocesses historical user interactions.

Confidence: 82%Severity: 64%
AnomalyLOW
skillopt.ts

The fragment does not show clear malicious intent or common supply-chain malware indicators. It is a local LLM benchmarking utility with legitimate filesystem, subprocess, and network behavior. Review is warranted before use with sensitive Claude logs or untrusted --base/--factory/--staged inputs: prompts and outputs can leave the host, and rollout executes a shell script with inherited environment privileges. Use a trusted endpoint and factory repository, restrict permissions, and treat mined datasets as sensitive.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/a-canary%2Farc-skills%2Fskillopt-lite%2F@634eeed8b188b3d8d5ef6e0b9ac734796878a0c74d83474df98e81f8403407d4
Security Audit — socket — skillopt-lite