add-compact

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The add-compact skill aligns with its stated purpose: it implements a manual compaction command restricted to trusted contexts, archives transcripts prior to compaction, and forwards a new session ID to maintain continuity. No external data exfiltration, credential harvesting, or autonomous actions are implied. The footprint—code changes to internal files, unit tests, and container handling—appears proportional to the described functionality. While the plan references several operational commands (build/restart) typical of deployment steps, these are not executed by the agent in normal operation according to the description. Overall, the risk posture is low-to-moderate and consistent with a developer tooling enhancement.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-compact%2F@b7c8d60267207fca9566f2039c260e75ad43eec0