cass

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill's core capabilities mostly match its stated purpose, but its footprint is broad and sensitive: it aggregates many local agent histories, can use a decryption key, discovers SSH hosts, syncs data across machines, and may install itself remotely. The main trust concern is the raw GitHub pipe-to-shell installer from a personal account. This looks more like a high-sensitivity developer tool with meaningful supply-chain and remote-access risk than outright malware.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/dicklesworthstone%2Fcoding_agent_session_search%2Fcass%2F@057d7617c09b13aa67b8d3aaaa30a0e2e728cd0f