cold-start

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent for a data-bootstrap skill, and the offline Takeout path is proportionate. However, the live-sync design routes highly sensitive personal data and delegated authority through ClawVisor instead of official service APIs, asks for expansive cross-account scope, and chains to additional skills. This is not confirmed malware, but it creates a high privacy and trust risk that is disproportionate unless the user explicitly accepts a third-party credential gateway.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Aug 29, 2026, 06:18 PM
Package URL
pkg:socket/skills-sh/praxstack%2Fskills-and-personas%2Fcold-start%2F@c5c0b7776bb9f5d2d5fad601aa2dd2b99628c5a9e2596c90fe2699d3a933ec9f
Security Audit — socket — cold-start