todo-creation

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The todo-creation skill implements a local-file tooling workflow with no external network or credential handling. Its footprint is coherent with its stated purpose: it reads user input, creates a new numbered markdown file with frontmatter in a local directory, and updates status after content is provided. The primary security considerations are ensuring proper input sanitization, safe path resolution, and that the bundled script cannot be replaced or redirected to an untrusted source. Overall, the risk is benign with moderate caution around path handling and script integrity.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/erich3000%2Fji-agent-skills%2Ftodo-creation%2F@129fc9e9adce898bec5ceffa928eec94c993481b