safe-encryption

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is encryption, but the skill’s footprint is broader and riskier than necessary: it auto-installs an unverifiable binary, encourages browser-based secret handling, accesses ~/.ssh private keys, performs networked Gist/GitHub workflows, and includes transitive skill installation instructions. This is not confirmed malware, but it is a high-risk skill with disproportionate credential and execution trust requirements.

Confidence: 87%Severity: 90%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/grittygrease%2Fsafe-encryption-skill%2Fsafe-encryption%2F@b3fbb630c4a1acb07bea091038f685616fbe6826
Security Audit — socket — safe-encryption