signal-history-search

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
README.md

The fragment describes a utility that could legitimately search local Signal messages by querying an encrypted SQLite database. However, it raises privacy concerns (access to private messages) and supply-chain risks (npx install from potentially untrusted sources). There is no evidence of malicious code in the fragment itself, but misconfiguration or weak provenance controls could enable privacy leakage or supply-chain tampering. Recommend validating the skill’s provenance, implementing strict integrity verification (e.g., signed packages, hash checks), and enforcing least-privilege, local-only processing with opt-in exports and clear user consent.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:44 AM
Package URL
pkg:socket/skills-sh/nicolaischmid%2Fagent-inbox-tools%2Fsignal-history-search%2F@1e2462069b7f53bbe4d3a7e59a00eab26ec500b0