neuroskill-sleep
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileThe neuroskill-sleep skill documentation and command patterns are broadly coherent with a legitimate developer tool for local EEG sleep staging and session embedding visualization. Data flows are predominantly local, with only localhost network activity shown, which is consistent with a self-contained CLI service. However, there are modest security concerns around potential accidental exposure of sensitive EEG/embedding data if logs or endpoints are misconfigured, and the absence of explicit data protection controls or access restrictions. Overall, the footprint is Benign to Suspicious (leaning toward Benign) given the local-first design, but the combination of sensitive data handling and potential local service exposure warrants modest security attention and clear documentation on data-at-rest protections and endpoint binding defaults.