jsonl-digest

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Mostly coherent local memory-digestion skill with no evident exfiltration or credential harvesting, but it relies on an unverifiable local executable script and performs autonomous file writes from transcript-derived content. Overall this is better classified as SUSPICIOUS/VULNERABLE due to supply-chain trust and transcript-to-write integrity risk, not as confirmed malware.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 03:11 PM
Package URL
pkg:socket/skills-sh/kcchien%2Fskills%2Fjsonl-digest%2F@5a0aea3d9ebfd9f9d66f28ea2f169caf91cb4c9a