friction-log

Warn

Audited by Socket on Jun 2, 2026

1 alert found:

Anomaly
AnomalyLOW
passive/SKILL.md

SUSPICIOUS: the skill’s purpose largely matches its behavior, but it exports conversation-derived data to a third-party hosted endpoint and can do so automatically at session end with limited transparency. The publisher/repo/endpoint relationship appears coherent, so this is not confirmed malware, but the external reporting flow, silent failure behavior, and transitive skill install model make it medium risk.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Jun 2, 2026, 12:20 AM
Package URL
pkg:socket/skills-sh/aurorascharff%2Fagent-friction-skill%2Ffriction-log%2F@945d109afadd5dfbd3dbff46992129c17ec7b098
Security Audit — socket — friction-log