second-brain
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the purpose is coherent for a personal knowledge skill, but the real execution path hinges on an undocumented `sb` executable whose provenance cannot be verified from the provided evidence. No confirmed credential theft or overt exfiltration is shown, yet the missing install trail and underspecified external data flows make the skill high risk for trust and review.
Confidence: 83%Severity: 80%
Audit Metadata