creative-brief

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core brief-writing purpose is benign, but the skill's actual footprint is broader than necessary: it reads local state, writes config markers, invokes opaque RMBC helper binaries, conditionally logs telemetry, opens a promotional video, and changes shared workspace state. No confirmed malware or overt credential theft is present, but the telemetry/data-flow claim is not independently verifiable and the auxiliary behaviors are disproportionate for a simple creative-brief skill.

Confidence: 74%Severity: 52%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/coleschaffer%2Fdtc-copywriting-skills%2Fcreative-brief%2F@45173af2b90e1d53d269b09ef7ef337439713b19631689400ad0186b69ca0301
Security Audit — socket — creative-brief