daily-debrief

Warn

Audited by Socket on Aug 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core reporting behavior is plausible, but it is not self-contained. It requires an unverifiable companion skill/script (mission-log harvest.py) and exposes an arbitrary post-command hook that can upload report contents anywhere. No direct credential theft is shown, but install trust and outbound-command extensibility are disproportionate enough to treat the skill as high security risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 9, 2026, 01:04 PM
Package URL
pkg:socket/skills-sh/tingyulu%2Fmyr2d2%2Fdaily-debrief%2F@00442e1f1befe9711a759a104b397ebe515ea79060bd97e97fb3bad544a6378c
Security Audit — socket — daily-debrief