NYC

password-recovery

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Generic secret pattern detected This skill is coherent with its stated purpose (forensic password/data recovery). It contains instructions to read local files, run standard forensic tools (strings, xxd, file, binwalk) and to perform byte-level analysis and fragment reconstruction. There are no network calls, hidden downloads, or obfuscated code that indicate supply-chain or exfiltration malware. The primary risk is misuse: the guidance is powerful and can be used to extract secrets if an unauthorized operator runs these commands on an environment they can access. Overall it is functionally benign documentation for forensics but sensitive in nature — treat as privileged guidance and restrict use to authorized investigations. LLM verification: The document is a legitimate forensic guidance skill for recovering passwords and sensitive fragments from disk images and binary data. It contains no embedded malware, network exfiltration code, hard-coded real credentials, or obfuscation. The primary security concern is operational: the instructions enable extraction and printing of secrets and therefore can be misused if executed with excessive privileges or without authorization. Recommend using this skill only in controlled, authorized fore

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:59 PM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fpassword-recovery%2F@ea9f4babbe1b90029fa05a781364f00ecaff2c5b