randroid
Audited by Socket on Oct 7, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill’s purpose and capabilities mostly align, but it depends on executing a locally discovered vibereview binary with limited provenance. Because the CLI is not distributed through a standard registry and lacks a strong verifiable release trail, the install/execution trust risk is high even without clear malicious behavior. No obvious credential exfiltration or hidden data routing is shown in the instructions.
This is a small hook configuration that delegates all meaningful behavior to an external stop-hook.sh executed on “Stop” events. The description’s claim of intercepting session exit and re-feeding prompts to create a self-sustaining loop is atypical and could indicate non-terminating or repeatedly reinforcing behavior. No direct malicious actions are visible in this fragment, but the command execution sink makes the package’s risk primarily dependent on the contents and trustworthiness of stop-hook.sh, which is not provided here; it should be reviewed end-to-end for data handling, persistence, and any unintended looping behavior.