session-compound

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core reporting behavior is coherent and mostly local, but the skill also performs ecosystem skill discovery and explicitly sets up downstream `skills add` installations. That transitive trust chain, combined with unpinned `npx` execution and access to sensitive session logs, makes this higher-risk than a normal summarization skill, though there is no clear evidence of direct credential theft or malicious exfiltration.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 11, 2026, 08:30 AM
Package URL
pkg:socket/skills-sh/Ben2pc%2Fg-claude-code-plugins%2Fsession-compound%2F@81581556d5af5619437753e5a72a8459893abf87