Migrate

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s broad file-ingestion and local write behavior largely match its migration purpose, but two trust issues stand out: undocumented execution of core local PAI tools with no verifiable provenance in the snippet, and a mandatory POST to an unexplained localhost service unrelated to content classification. This is not confirmed malware or credential theft, but the install/execution trust and data-flow integrity are weaker than expected for a benign local migration skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 2, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/danielmiessler%2Fpersonal_ai_infrastructure%2Fmigrate%2F@4e2e553239bca27f70a58e3c594cc8fa5d63e79d