daily-update

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the drafting behavior is narrowly scoped and mostly coherent, but the skill's trust boundary depends on a non-official third-party Linear CLI that may hold/use a real Linear API key, and it can trigger transitive skill installation. No clear malicious exfiltration is shown, but the install/credential trust model is disproportionate enough to warrant caution.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/BenjaminG%2Fai-skills%2Fdaily-update%2F@877704b7ecf0d36cbc78725f59777574b40fb92a