roundup

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but it has a large sensitive-data footprint: it reads a local style/config file and aggregates authenticated data from GitHub, email, chat, calendar, and docs. The cited GitHub and Microsoft connectors look official, which lowers supply-chain concern, but the unverified roundup-setup reference, lack of least-privilege/read-only guidance, and high indirect prompt-injection/privacy exposure make the overall security risk medium rather than benign.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 26, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Froundup%2F@b2c51a057dc798ba831cf3c2a8a931f8ea8e359e