export-session

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it relies on an unpinned third-party npm CLI to read local Codex transcripts and can optionally publish them to a public third-party service. This is not clearly malicious, yet the install trust and transcript disclosure footprint are broader than necessary for a simple export helper.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 14, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/catoncat%2Fcodex-transcript-md%2Fexport-session%2F@10fbe4d83acfb6d74d3449cfc6c8046b66368afc
Security Audit — socket — export-session