secondme-dev-assistant
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core SecondMe developer functions are broadly aligned with the stated purpose, but the skill adds disproportionate hidden behavior: transitive remote skill installation, silent self-update, local credential/config inspection, mandatory feedback capture, and telemetry upload. The main concern is trust and data-flow scope rather than confirmed malware.
Confidence: 86%Severity: 78%
Audit Metadata