zettel-brainstormer

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill description is coherently aligned with its stated purpose of enabling local note brainstorming and drafting. It relies on local file I/O for reading notes and writing drafts, with optional remote search components controlled by configuration. There are no explicit malicious patterns in the fragment itself, but the workflow includes a setup step that could pull dependencies, and a configurable web search path that could introduce external data flows. Overall, the footprint is proportionate to its stated purpose; however, the presence of setup-driven dependency installation and optional external searches warrants caution and visibility into which sources are trusted. Recommend ensuring dependencies are pinned, external searches are opt-in and cite sources, and that local note references are not unintentionally sent to external services without explicit user consent.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/hxy9243%2Fskills%2Fzettel-brainstormer%2F@86632632dac5a99f5238040517f949ce52e6d565