sell-agent-sessions

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches selling selected agent sessions, but the install path is inconsistent with verified official Cookiy documentation and the referenced uploader/package could not be publicly confirmed. Its default behavior also pushes autonomous installation and a persistent detached background process, which is proportionately risky for a monetization skill handling sensitive local histories.

Confidence: 87%Severity: 76%
SecurityMEDIUM
README.md

The supplied material is not source code and does not provide enough evidence to confirm malicious behavior. It explicitly promotes collecting and uploading AI-agent sessions and installing an external skill globally via `npx`, presenting significant privacy, confidentiality, and supply-chain risks. Review the referenced repository, package metadata, install scripts, uploader implementation, data sanitization logic, and network destinations before installation or use.

Confidence: 96%Severity: 70%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:51 AM
Package URL
pkg:socket/skills-sh/cookiy-ai%2Fsell-sessions-skill%2Fsell-agent-sessions%2F@c107696ec1f005d9b32f5b40de939e9edd76b177
Security Audit — socket — sell-agent-sessions