kb-librarian

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s file access and knowledge-base maintenance behavior mostly fits its stated purpose, but it depends on an unverified local script (~/.claude/scripts/kb-index.py) and ingests arbitrary external content while retaining write access. There is no clear evidence of credential theft or malicious exfiltration, but the unverifiable executable and prompt-injection exposure make the skill high risk.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Aug 15, 2026, 03:24 AM
Package URL
pkg:socket/skills-sh/khanhhuyenngo985-sys%2Fcharacter-scene-design-skills%2Fkb-librarian%2F@8f63874769c469d114067433d756cc6e168d8e3b5e59e6af8d4bdca884912216
Security Audit — socket — kb-librarian