NYC

session-logger

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

No direct malware or obfuscated malicious code observed. The package/skill is plausible and functionally consistent with a session-logging utility, but it is over-privileged (Bash + broad read/write) and has risky UX (silent auto-save, encouragement to store sensitive info). These factors create a moderate security/privacy risk: unintentional persistence of secrets and potential downstream exposure. Mitigations: remove or tightly scope Bash, enforce explicit user confirmation for auto writes, implement file-read exclusions and secret redaction, and clarify that .gitignore is not a security control.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:08 PM
Package URL
pkg:socket/skills-sh/charon-fan%2Fagent-playbook%2Fsession-logger%2F@10a005cf38b187a1f7e64baf3b3e557b74661859