dreamtime

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core issue is unattended background autonomy: it silently reads personal context, performs open-ended web research, and directly rewrites persistent memory files without user review. There is no clear credential theft or malicious payload, but the combination of stealthy operation, untrusted web inputs, and write access makes the skill high-risk for integrity and prompt-injection abuse.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Mar 30, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/ascorbic%2Fmacrodata%2Fdreamtime%2F@beb4847cc82c970ec2e021fec5607d880fa78bc4
Security Audit — socket — dreamtime