extracting-session-data

Fail

Audited by Socket on Feb 13, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is functionally consistent with its stated purpose: it enumerates and extracts raw local Claude Code session logs using shell scripts and jq. There is no evidence of remote exfiltration, obfuscation, or hidden behaviors in the provided content. The primary risk is privacy-sensitive: the scripts intentionally read and emit raw conversation logs which may contain secrets or PII; that capability is legitimate for the stated use but must be treated as sensitive. Recommend adding explicit runtime warnings, redaction options, and limiting default behavior for very large sessions.

Confidence: 80%Severity: 35%
Audit Metadata
Analyzed At
Feb 13, 2026, 10:54 AM
Package URL
pkg:socket/skills-sh/bitwarden%2Fai-plugins%2Fextracting-session-data%2F@17713bf3fb1e5f1147effe52742dd84859441d32