spark-cli-knowledge-sharing

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches a knowledge-sharing tool, but the skill’s footprint is broad: it requires an external authenticated CLI, mandates routine network use before coding, and encourages uploading project-derived insights to a third-party knowledge base. The main concern is not overt malware but disproportionate data-sharing and credential-forwarding through an insufficiently verified binary/service boundary.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Apr 27, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/memcoai%2Fspark-cli-skills%2Fspark-cli-knowledge-sharing%2F@93a7068e1e601d8c57530b7c8bb2abc1101a5d9a
Security Audit — socket — spark-cli-knowledge-sharing