context-surfing

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is coherent for a context-management skill and data flow stays local, but the install model creates transitive trust in a personal third-party skill repo, and the hook/CLI integrations add medium supply-chain and prompt-injection exposure. No clear credential harvesting, exfiltration, or malicious intent is present.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 24, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/pskoett%2Fpskoett-ai-skills%2Fcontext-surfing%2F@49c1fc4973df9276f47bd976e28474d22e96dbce