secondme-dev-assistant

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core SecondMe developer functions are broadly aligned with the stated purpose, but the skill adds disproportionate hidden behavior: transitive remote skill installation, silent self-update, local credential/config inspection, mandatory feedback capture, and telemetry upload. The main concern is trust and data-flow scope rather than confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 10, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/mindverse%2Fsecond-me-skills%2Fsecondme-dev-assistant%2F@7d633bcbcfd444d9712a750505055372aba43e83