daily-next

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is coherent with its stated purpose of daily task orchestration and context gathering. However, it introduces notable credential and data handling risks, primarily around downloading Jira attachments using API tokens and transferring attachments to a temporary /tmp path. The combination of local task state updates, external service calls, and credentialed downloads constitutes a non-trivial security footprint. Without mitigations (e.g., pinned/verifiable binaries, minimized credential exposure, explicit secure cleanup, encrypted storage, and restricted API scopes), the skill should be treated as SUSPICIOUS with Elevated scrutiny recommended before deployment in a production or shared environment.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 12, 2026, 09:38 PM
Package URL
pkg:socket/skills-sh/benjaming%2Fai-skills%2Fdaily-next%2F@5835f43c08e077cc9d51696cb46078e0f3f62c3a