checkit

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core research behavior is mostly coherent with the stated purpose, but the skill crosses into disproportionate autonomous action by requiring the agent to persist notes and report only after the fact. Risk is increased by ambiguous-intent execution, reliance on an unverifiable local `video_ingest.py` workflow, local browser-cookie use for gated content, and optional routing through non-official third-party social-content services. Not confirmed malware, but it is a medium/high-risk skill due to autonomy and trust-boundary expansion.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 7, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fcheckit%2F@b3f77feb2ee8db33b9c190628119442b54b1f779973975fb7c76c6533c1e088e
Security Audit — socket — checkit