keepflash

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a note-management skill, but the bootstrap design is risky because it re-checks GitHub on every activation, trusts a mutable main branch, and delegates future behavior to downloaded runtime files and CLI paths. This is primarily a supply-chain and transitive-trust problem rather than confirmed malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Aug 15, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/dante-is-shipping%2Fkeepflash-skills%2Fkeepflash%2F@04d38751ace35b16936f127305420c47e7d45b19a8fc954ab6e62f8d3430dedd
Security Audit — socket — keepflash