session-to-agent
Warn
Audited by Socket on May 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's main behavior aligns with its stated purpose, but it expands trust to an external CLI and additional skills, and it converts potentially untrusted session content into a reusable autonomous agent with memory. No clear credential theft or third-party exfiltration is shown, so this is not malicious, but the supply-chain and transitive-trust footprint is larger than a simple local formatter/extractor.
Confidence: 80%Severity: 56%
Audit Metadata