sell-agent-sessions
Audited by Socket on Sep 20, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill's stated purpose matches selling selected agent sessions, but the install path is inconsistent with verified official Cookiy documentation and the referenced uploader/package could not be publicly confirmed. Its default behavior also pushes autonomous installation and a persistent detached background process, which is proportionately risky for a monetization skill handling sensitive local histories.
The supplied material is not source code and does not provide enough evidence to confirm malicious behavior. It explicitly promotes collecting and uploading AI-agent sessions and installing an external skill globally via `npx`, presenting significant privacy, confidentiality, and supply-chain risks. Review the referenced repository, package metadata, install scripts, uploader implementation, data sanitization logic, and network destinations before installation or use.