agent-export

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose mostly matches its behavior, but it exports very sensitive agent state—including persona/system-prompt-derived content and arbitrary files—and uploads it to a fly.dev relay whose first-party ownership is not evident from the skill alone. That makes the data flow disproportionate and trust-sensitive even if the feature is framed as migration.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fagent-export%2F@3995d2d0df08aebff97bdcf1c78624dda0ddcd73fa72732201e485b3df8fc851
Security Audit — socket — agent-export