content-converter

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malware or obfuscated payloads detected in the provided fragment. The most significant security concern is the behavioral directive to automatically read and write a local memory/preferences.md file (via an abstract '@path'), which increases local data-exposure and persistence risk if the agent has filesystem and/or external connector privileges. Recommend changing memory access to explicit opt-in, adding validation/sanitization, clarifying the concrete sandboxed memory path, and preventing storage of secrets. With those mitigations, the skill can be considered low-risk for distribution.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 21, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/ma2ong%2Fclaude-skills-collection%2Fcontent-converter%2F@e5607a495180af76ca8d0b17ec4a2d760f10c26e