secondme-skill

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose broadly matches its orchestration behavior and local-first framing, but core capability is delegated to unverified downstream skills and training toolchains. No direct credential harvesting or exfiltration is shown here, yet the transitive trust chain and medium supply-chain exposure make the overall footprint riskier than a purely local documentation/orchestration skill.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
May 13, 2026, 12:38 PM
Package URL
pkg:socket/skills-sh/acnlabs%2Fopenpersona%2Fsecondme-skill%2F@4d0ec4345c19b5f973128bf51c71f82182c112a9
Security Audit — socket — secondme-skill