rageprompt
Audited by Socket on Jul 17, 2026
2 alerts found:
Securityx2This module is best characterized as a sensitive local data harvesting/scraping tool for AI/editor chat history. It performs broad discovery and extraction of user prompts across many installed products, uses heuristic redaction that can be disabled, and then outputs the collected content to stdout. While it does not demonstrate classic malware behaviors (no network calls, no persistence, no reverse shells) in this fragment, the privacy/data-theft risk is substantial due to the intentional collection and export of potentially sensitive conversation text.
SUSPICIOUS. The skill’s stated purpose matches its behavior, but that behavior is inherently privacy-invasive: it mass-reads local AI histories across many tools and publishes selected content to an external, weakly verifiable domain. The main risk is data exfiltration and autonomous public posting, not confirmed malware.