groove-utilities-prime

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The groove-utilities-prime skill presents a coherent and purpose-aligned footprint: it reads local Groove configuration, optionally includes identity context, and performs a daily version check via a standard API call. Data flows are consistent with its goal of informing the agent about current config and constraints. There are no evident credential-forwarding, remote file exfiltration, or unauthorized third-party payloads. The main privacy considerations are the potential exposure of local config and optional identity data to the user, which is expected in a context-loading utility. Overall, the risk posture is benign with minor privacy considerations; no malicious behavior detected.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/andreadellacorte%2Fgroove%2Fgroove-utilities-prime%2F@b8b29b5e2f48bb1a51a8ad6f7337e1c8ded826b1