cosense

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s read/write Cosense capabilities match its stated purpose, but install trust is weaker than it should be because it uses an unpinned `bunx`-executed npm CLI whose official provenance is not established in the provided evidence. Handling a raw `connect.sid` session cookie and passing it to that CLI is proportionately risky. No clear malicious exfiltration or unrelated capability is shown, but the credential-forwarding and runtime package execution make this higher-risk than a typical documentation-only skill.

Confidence: 77%Severity: 68%
Audit Metadata
Analyzed At
Apr 6, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/mrsekut%2Fcosense-cli%2Fcosense%2F@bb1450c86f817c48552fd8ab0388ac0f4d729ad0
Security Audit — socket — cosense