dot-dash

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s monitoring purpose partly matches its dashboard behavior, but it also adds high-risk prompt injection and broad transcript streaming across all sessions. No external malware or credential theft endpoint is shown, yet the combination of local shell execution, token exposure, LAN-accessible transcript UI, and direct prompt manipulation makes the skill high-risk and disproportionate for a simple dashboard helper.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fdot-dash%2F@691a527f745ac9141161e062065ed456784aad7f