future-predictor
Audited by Socket on May 9, 2026
2 alerts found:
Anomalyx2No actual code fragment was provided—only project description text. There is no direct evidence of malware. However, the described intended behavior includes reading sensitive local artifacts (IDE open files and bash history), which is a high-risk design area if the implementation sends that data off-host or logs it insecurely. Review the real implementation for network/telemetry usage and data handling controls.
SUSPICIOUS. The core purpose is coherent with reading git diff, but the skill's footprint expands to IDE open files and bash history, which is broader and more privacy-invasive than necessary. There are no external installs, remote endpoints, or clear exfiltration paths, so this is not malicious, but it is medium risk due to disproportionate local data access.