sync-feedback

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign: The skill operates strictly on local feedback data and, when exporting, targets the legitimate GitHub API. Data access is scoped to local filesystem for processing and to GitHub for export. No credential harvesting or covert data exfiltration patterns are evident in the described workflow. The only external contact is GitHub during export, which is expected given the feature set. Overall footprint is coherent with the stated purpose and proportionate to the task.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:51 AM
Package URL
pkg:socket/skills-sh/jpoutrin%2Fproduct-forge%2Fsync-feedback%2F@021d1ea629f95bafbdec8b81dd3501e1e3692ada