NYC

debugger

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The debugger skill appears functionally appropriate and contains standard, non-malicious debugging guidance. The main security concern is not active malware but rather privacy and supply-chain risk: automatic background hooks combined with broad filesystem and command execution permissions create a credible path for accidental or intentional capture and persistence of sensitive information (environment variables, credentials, logs, code). Before using this skill in sensitive environments, require explicit opt-in for hooks, add clear documentation of data handling and storage, apply sanitization/redaction to captured outputs, and enforce least-privilege for tool permissions. No evidence of obfuscation or active malicious behavior was found in the provided file.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:37 PM
Package URL
pkg:socket/skills-sh/charon-fan%2Fagent-playbook%2Fdebugger%2F@770fcbe2b8dc26e2152e2534557c4c75fbb5871f