Scribe

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

[Skill Scanner] Skill instructions include directives to hide actions from user Benign in stated purpose and intent; however, the fragment lacks implementation details for memory, persistence, and privacy controls. If integrated, ensure explicit data-handling policies, consent, data minimization, and secure storage to avoid privacy risks. LLM verification: This is a benign-seeming human-readable skill specification that, if implemented, would grant broad access to user conversation data and enable persistent cross-session memory. The document itself contains no executable malicious code, hard-coded secrets, or network calls. However, it explicitly instructs stealthy recording ('document patterns silently') and omits any privacy, consent, storage, or access controls. That design choice introduces a meaningful supply-chain and privacy risk: implemen

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:23 AM
Package URL
pkg:socket/skills-sh/nikhilvallishayee%2Funiversal-pattern-space%2Fscribe%2F@00425c05c0bf6c695dfdf71a0607942f841242d0