Investigation

Warn

Audited by Socket on Feb 28, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
PrivateInvestigator/SKILL.md

Overall, the PrivateInvestigator skill aligns with its stated purpose of ethically performing public-data-based people search using parallel agents. The main concern is the unusual mandatory local curl notification that could be exploited if the local endpoint is exposed. Otherwise, no credential access, no remote exfiltration, and no executable downloads are evident in the provided fragment. Recommend ensuring the local notify endpoint is properly secured, sandboxing is enforced for customization loading, and that the workflow only engages public data sources as described.

Confidence: 75%Severity: 75%
SecurityMEDIUM
OSINT/SKILL.md

The OSINT skill specification presents a governance-aligned, OSINT-oriented workflow that relies on public sources and explicit authorization. The primary concern is the mandatory localhost notification curl call, which should be clearly documented as a local orchestration hook and restricted to trusted runtimes to avoid covert signaling or unnecessary exposure. Aside from that, there is no evident credential harvesting or external data exfiltration in the fragment. Recommend documenting the notify mechanism, validating its necessity, and ensuring strict sandboxing for local customization loading. Overall, the design is plausible and proportionate for authorized OSINT tasks with appropriate governance, provided the local inter-process signaling is secured.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/danielmiessler%2Fpersonal_ai_infrastructure%2Finvestigation%2F@d838ff437b223f42469ef2b6d2c453227aed1b2c