motion

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Motion Skill presents a coherent high-level purpose (AI-powered calendar and task management) but embeds a notable supply-chain risk via curl|bash installation from an external URL and unverifiable binaries. It also relies on multiple credential inputs and browser automation for authentication, leading to potential credential exposure and data flow to external services. The combination of unverifiable install, mixed credential handling, and browser automation creates elevated security risk and warrants treating this as SUSPICIOUS to HIGH risk pending stronger supply-chain assurances (checksum/signature verification, official registries, and explicit, bounded data-flow diagrams).

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:44 PM
Package URL
pkg:socket/skills-sh/NeverSight%2Flearn-skills.dev%2Fmotion%2F@f57c93ec97512ecc75c587e51a6ce23bdd474eb7