agent-carnet

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose and described data flows are coherent for a local note manager, with no signs of credential harvesting, network exfiltration, or covert behavior. The main risk is install/execution trust: it relies on an external `agent-carnet` binary whose source and publisher cannot be verified from the provided evidence, so the skill is suspicious on supply-chain grounds rather than malicious in function.

Confidence: 82%Severity: 70%
Audit Metadata
Analyzed At
May 13, 2026, 05:27 AM
Package URL
pkg:socket/skills-sh/yamadashy%2Frepomix%2Fagent-carnet%2F@b909ef6cf27c2b99b7309197881ba9260d5b8137