Scribe
Audited by Socket on Feb 16, 2026
1 alert found:
Anomaly[Skill Scanner] Skill instructions include directives to hide actions from user Benign in stated purpose and intent; however, the fragment lacks implementation details for memory, persistence, and privacy controls. If integrated, ensure explicit data-handling policies, consent, data minimization, and secure storage to avoid privacy risks. LLM verification: This is a benign-seeming human-readable skill specification that, if implemented, would grant broad access to user conversation data and enable persistent cross-session memory. The document itself contains no executable malicious code, hard-coded secrets, or network calls. However, it explicitly instructs stealthy recording ('document patterns silently') and omits any privacy, consent, storage, or access controls. That design choice introduces a meaningful supply-chain and privacy risk: implemen