transcript-fixer

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core transcript-correction behavior is coherent, and the `uv` installer appears official, but the skill unnecessarily reads shell config files to harvest API keys instead of requiring explicit user-provided credentials. That disproportionate credential access raises medium security concern without enough evidence for confirmed malware.

Confidence: 87%Severity: 55%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/seaworld008%2Fcommonly-used-high-value-skills%2Ftranscript-fixer%2F@f8b8f5e9f3ad7679850bed1111ec95ae8bc53cde2b70678459f2022e33cb0765
Security Audit — socket — transcript-fixer