debrief

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core behavior—saving a local debrief report—is coherent with the stated purpose, and file access is mostly well-scoped to ./.ai/reports. The main concerns are the transitive skill installation via an unpinned `npx` path with repo/documentation mismatch, plus the instruction to open the generated file without confirmation. This looks more like a moderately risky workflow skill than malware, but the dependency trust chain is not fully clean.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
May 14, 2026, 11:59 AM
Package URL
pkg:socket/skills-sh/PaulRBerg%2Fagent-skills%2Fdebrief%2F@34493b1b1d2a7c43fa25f476b94b9de2522c1797