keepflash
Warn
Audited by Socket on Aug 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a note-management skill, but the bootstrap design is risky because it re-checks GitHub on every activation, trusts a mutable main branch, and delegates future behavior to downloaded runtime files and CLI paths. This is primarily a supply-chain and transitive-trust problem rather than confirmed malware.
Confidence: 87%Severity: 78%
Audit Metadata