screenpipe-setup

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose of setting up local screen OCR, and its main external install path uses a legitimate registry. However, it combines persistent screen capture, silent telemetry/logging, and execution of unreviewed local dex-core scripts/LaunchAgents, which makes the footprint more sensitive than a simple setup helper. No clear credential theft or hostile exfiltration is shown, so this is not malware, but it carries meaningful privacy and security risk.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fscreenpipe-setup%2F@6285e86ff766655c7e3522639946e667e0288ba6
Security Audit — socket — screenpipe-setup