NYC

capability-assessment

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's functionality (reading local Claude chat history to produce a growth report and sending it to Slack) is coherent with its stated purpose. There is no clear evidence of active malware in the provided instructions. However, significant privacy and supply-chain risks exist: the design specifies reading sensitive local history and routing report contents through unspecified intermediary tooling (Rube MCP) and Slack, without describing redaction, consent, or data retention controls. The greatest risk is accidental exfiltration of secrets and private code. If implemented with documented, local-only operations plus robust redaction and explicit user consent, the risk is manageable. If implemented via remote or opaque intermediaries, treat the package as high-risk for data leakage and require additional review.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:00 PM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fcapability-assessment%2F@6c4394febc2032fb75871c4c0958ca6981be468c