summarize-work
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The summarize-work skill is coherently scoped to gather session data from a local OpenCode server (or SQLite fallback) and generate narrative summaries for commits, PRs, or documentation. Data access is restricted to local sources, with no evident credential handling or external data exfiltration. The footprint aligns with its purpose as an on-device summarization tool, and security concerns are low given localhost-based operation. The only notable precaution is to ensure the OpenCode server is secured and not exposed publicly, and that the agent’s execution environment cannot be coerced into running arbitrary local reads or commands beyond the described endpoints.
Confidence: 98%
Audit Metadata