stacktree-sideshow-handoff
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's sharing behavior is broadly aligned with its stated purpose and the referenced Stacktree domains/tools look same-service and legitimate, but the actual publish mechanism depends on an unseen local script that can exfiltrate content or credentials without independent verification. The main risk is proportionate but high-impact outbound publication plus unverifiable execution details, not confirmed malware.
Confidence: 84%Severity: 72%
Audit Metadata