daily-debrief
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core reporting behavior is plausible, but it is not self-contained. It requires an unverifiable companion skill/script (mission-log harvest.py) and exposes an arbitrary post-command hook that can upload report contents anywhere. No direct credential theft is shown, but install trust and outbound-command extensibility are disproportionate enough to treat the skill as high security risk.
Confidence: 84%Severity: 78%
Audit Metadata