smart-session-start

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and it lacks direct install, credential theft, or code-execution behavior. Risk comes from mandatory automatic activation and reliance on unverified external MCP servers that receive recalled project context, creating moderate trust and data-flow concerns.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Mar 19, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/anortham%2Fmcp-toolbox-workflows%2Fsmart-session-start%2F@6cb59abb75690be59ce10e9e23eca30892330b14