synapse

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose mostly matches its local file access, but the automatic generation of new skills without user review is disproportionate and creates a high-risk transitive trust chain. Install provenance is same-repo and not overtly malicious, yet mutable ZIP distribution plus unattended cron/git-hook execution raises meaningful security risk.

Confidence: 86%Severity: 77%
Audit Metadata
Analyzed At
Apr 17, 2026, 03:04 PM
Package URL
pkg:socket/skills-sh/bacoco%2FEvolveSkill%2Fsynapse%2F@2b6e35b0866bfb6e56f7c268a7f3636ff703b1dd
Security Audit — socket — synapse