ai-daily-digest

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core RSS-to-digest workflow is coherent with the stated purpose, and there is no clear credential harvesting or exfiltration path. However, the skill uses unpinned transient npm executions, includes a weaker-security `--no-sandbox` Chrome render path, and processes untrusted external content while retaining write/exec capabilities, making it a medium-risk skill rather than benign.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/jssfy%2Fk-skills%2Fai-daily-digest%2F@219e6f66e59470c8d361df27b1b47f92cc4b7a0f