brainstorming

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core brainstorming purpose is legitimate, but it expands its footprint with mandatory external MCP usage, transitive skill invocation, and write/commit behavior after inspecting untrusted content. The install provenance cited is mostly official, so this is not confirmed malware; the main concerns are scope expansion, prompt-injection exposure, and downstream trust chaining.

Confidence: 83%Severity: 61%
AnomalyLOW
scripts/stop-server.sh

The code is a legitimate server cleanup script with no clear malicious behavior. It has a security risk because the /tmp-only deletion check is based on a string prefix rather than a canonical path, allowing traversal-style destructive deletion if an attacker can control SESSION_DIR. The unvalidated PID file also permits unintended process signaling. Input validation, canonicalization, and strict PID validation are recommended.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:36 AM
Package URL
pkg:socket/skills-sh/galyarderlabs%2Fgalyarder-framework%2Fbrainstorming%2F@c9ec2afadc542173909c53c7720d507a249a4cc042aacd4f5c6ff03836574e7a
Security Audit — socket — brainstorming