digest

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The digesting and logging behavior broadly fits the claimed purpose, and the xAI endpoint is official, but the trust boundary is broken by `./secretcurl`: an unverifiable local executable receives `XAI_API_KEY` and performs the authenticated call. Combined with autonomous notification and ingestion of untrusted external content, this makes the skill high risk despite a plausible use case.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Aug 20, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/aeonfun%2Faeon%2Fdigest%2F@b22d2695ef76c71fe38de862a377c61372176fd670a89115c7e2c0bfcae2b983
Security Audit — socket — digest