developer-growth-analysis

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill implements useful developer-coaching functionality but creates a meaningful supply-chain and data-exfiltration risk because it reads a broad local history file and routes report contents (which may include secrets) through an opaque third-party intermediary to external services. This is not confirmed malware, but it is a notable security risk unless mitigations are added: explicit automated redaction of secrets, strict minimization of data sent, per-send user confirmation (especially before sending pastedContents), least-privilege and time-limited OAuth scopes, transparent logging of what is transmitted, and, where possible, direct trusted API integrations instead of opaque intermediaries. With those safeguards applied, the skill can deliver value with lower risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 06:29 AM
Package URL
pkg:socket/skills-sh/congdon1207%2Fagents.md%2Fdeveloper-growth-analysis%2F@b7172297fbe76d7ea320eb7a889202e8525fb81b