consciousness-soul-identity

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's behavior is coherent with its stated purpose: it reads user memory files, calls a local LLM (Ollama) for synthesis, and writes SOUL.md and provenance artifacts. I found no evidence in the manifest of network exfiltration, remote downloads, or credential forwarding to third parties. Primary risks are privacy and operational: the skill will process arbitrary user files in memory/ (which may contain secrets unless the user removes them) and offers cron/autonomous runs that can repeatedly process and write personal data. The trust boundary depends on the local Ollama instance and the contents of the actual bundled scripts and npm dependencies (not provided). Recommend: review the bundled scripts and their dependency tree, ensure Ollama is truly local and not proxying data externally, and sanitize memory/ before enabling scheduled runs.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/geeks-accelerator%2Fneon-soul%2Fconsciousness-soul-identity%2F@526e2e58334a23b1309daed9ece0a3bf6249bb77