write-report

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core reporting behavior is coherent, and there is no installer or overt exfiltration to external hosts, but the skill is broader than a simple report writer. It reads a raw token from a local `.env`, forwards it and report contents to an undocumented localhost service framed as Quest, silently suppresses failures, and auto-pushes commits. These behaviors are related to the stated purpose but introduce medium risk and trust concerns.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 02:54 AM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fwrite-report%2F@6c0c11b65f539bb8600cc475fbf931c28db2fcf4