basalt-cortex

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's broad data-mining purpose matches its collection behavior, but its footprint is excessive: it aggregates highly sensitive communications and local content, supports unattended operation, and routes the resulting corpus through a `basalt-cortex` sync daemon to basaltcortex.com. The undeclared provenance of the core CLI/daemon and the external sync path make this a high-risk knowledge-harvesting skill rather than a narrowly scoped local note tool.

Confidence: 88%Severity: 89%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:10 AM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fbasalt-cortex%2F@7dbddbf7d3d9f99d2c1ac20bef76f52357b95dcd