chronicle

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/docs/session-data.md

This is a benign synchronization tool and documentation for aggregating local Claude session data to a central host. The main security concern is accidental or intentional leakage of highly sensitive personal data (prompts, clipboard, env vars, credentials) to the aggregation host. Risks arise from misconfigured or untrusted destination hosts, the presence of a default DEST_HOST value ('orin'), and lack of client-side encryption or secret filtering. There is no clear indicator of malware in the code itself, but the operational privacy/exfiltration risk is real and significant if used improperly. Recommend: ensure DEST_HOST is set to a host you control, remove or encrypt secrets before syncing, add excludes for known secret files, and consider optional client-side encryption and destination verification.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:00 AM
Package URL
pkg:socket/skills-sh/fairchild%2Fdotclaude%2Fchronicle%2F@3b94a3f8be50a1efd0daf4048b400aee845b5b78