agent-in-sync

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill concept is coherent: it defines a disciplined, rule-based workflow for error handling that relies on a centralized KB (AgentInSync) and a per-user identity with an API key. The main risks arise from external data flows to a third-party service, potential insecure handling or exposure of error details, and the lack of explicit data-minimization/credential-security controls in the description. The behavior aligns with the stated purpose, but security and privacy controls around API keys, data transmission, and data retention should be clarified before deployment. Overall, the footprint is moderately risky (securityRisk about 0.40) but not clearly malicious; it should be considered suspicious if credential handling and data privacy policies are not properly managed. Recommend adding explicit credential storage guidelines, data minimization practices, and transport/security assurances.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/agentinsync%2Fagentinsync-skill%2Fagent-in-sync%2F@6df12fd15f7f8c0708f5d6e66d4a188bbce0817e