session-control

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This skill itself is narrowly scoped and plausible for its stated internal purpose: run a local script to manage session resume/fork behavior and update session state files. The principal security concern is executing a local shell script with workflow-controlled flags: without the script contents, there is a moderate command-injection and file-corruption risk. No direct evidence of network exfiltration or hard-coded credentials exists in this YAML fragment, but the lack of the script source prevents ruling out malicious behavior. Before approving broader use: review scripts/session-control.sh, ensure safe argument passing (no shell interpolation), add integrity checks, and restrict where the skill can be loaded.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/chachamaru127%2Fclaude-code-harness%2Fsession-control%2F@c7cd334598237c79bcc75372c89518815c8f5d34