analytics-clear

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The script performs a legitimate, local maintenance task: summarizing and removing an analytics directory. It contains no network operations, obfuscated code, or explicit credential exfiltration. The primary security risk is the unconditional use of rm -rf on a path constructed from the environment with no canonicalization or symlink checks, combined with an option that bypasses interactive confirmation. This can lead to accidental or adversarially induced destructive behavior. Recommend adding path canonicalization/validation, symlink checks, safer deletion semantics (trash/archive), and stricter handling of non-interactive confirmation to reduce risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/laurigates%2Fclaude-plugins%2Fanalytics-clear%2F@0f0260fbcb065297d43055921ca0b255d869598f