daily-briefing

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior matches its stated news-aggregation purpose and does not show clear credential theft or unrelated access. However, it automates Telegram posting and ingests substantial untrusted remote content, and it relies on a mutable third-party GitHub Gist for feed configuration. Overall this is coherent but medium-risk due to autonomous outbound delivery and prompt-injection exposure, not malware.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:24 AM
Package URL
pkg:socket/skills-sh/halanhuang2025-lgtm%2Fdaily-briefing-skill%2Fdaily-briefing%2F@6cc7aed315919f268e5114b201991876cd3af1d0