session-mesh

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherently aligned with its stated purpose of managing session topologies and sub-agent control in a distributed mesh. There are no obvious remote code execution or supply-chain risks; however, credential handling (SESSION_API_KEY in environment and headers) and high-impact actions (steer/kill) introduce risk if not coupled with robust access controls, audit logging, and secret management. Recommend explicit security controls: scoped permissions, secret vault integration, explicit TLS guidance, and detailed auditing of steer/kill/registry actions. Overall, the risk is MEDIUM (suspicious in areas of credential exposure and high-impact actions) but not malicious given the information provided.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Fsession-mesh%2F@d4e1aacb8f222dc3c33cdaac8fb3f42c94334f43