skill-system-memory

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/log-compaction.sh

This fragment behaves like a telemetry/compaction hook that persists session metadata and optionally captures and stores a transcript tail. There is no clear indicator of active malware or backdoor behavior, but there is a meaningful security/privacy risk: transcript_path is derived from untrusted JSON and can drive reading of arbitrary local files, and the captured content is persistently written to local JSONL and stored in PostgreSQL after base64 decoding. In environments with untrusted or attacker-influenced inputs, this warrants review of input validation, path restrictions, and retention/redaction controls.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:12 AM
Package URL
pkg:socket/skills-sh/arthur0824hao%2Fskills%2Fskill-system-memory%2F@6b50c8bf92bd11aad772d0ddc771ede55922b93d