stacktree-sideshow-handoff

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's sharing behavior is broadly aligned with its stated purpose and the referenced Stacktree domains/tools look same-service and legitimate, but the actual publish mechanism depends on an unseen local script that can exfiltrate content or credentials without independent verification. The main risk is proportionate but high-impact outbound publication plus unverifiable execution details, not confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 24, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/stevysmith%2Fstacktree-skill%2Fstacktree-sideshow-handoff%2F@b0d2dbf2e38a99ae668d0f2592c57d5849724c14c3e3b7b41b68e312a4b7f9f1