reminder

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Functionally coherent reminder skill that correctly describes parsing and creating local reminders via a Node script and CCCore. However, it requires the agent to execute shell commands with user-controlled arguments and interact with a local daemon and filesystem. Because the specification mandates actual Bash execution and does not prescribe argument escaping or other defenses, there is a moderate risk of command/argument injection and elevated local privilege misuse if the agent or scripts are compromised or input is not safely handled. No explicit hardcoded secrets or network exfiltration domains are present in this fragment, so this appears SUSPICIOUS but not overtly malicious in the content provided. Recommend implementing strict argument escaping, input validation, and limiting agent shell execution privileges; verify integrity of create-reminder.js and CCCore before use.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:02 PM
Package URL
pkg:socket/skills-sh/lostabaddon%2Fheadlessknight%2Freminder%2F@55889855c8b69c8e0f6dc23ff7281be3dce2dd1b