add-compact
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileThe add-compact skill aligns with its stated purpose: it implements a manual compaction command restricted to trusted contexts, archives transcripts prior to compaction, and forwards a new session ID to maintain continuity. No external data exfiltration, credential harvesting, or autonomous actions are implied. The footprint—code changes to internal files, unit tests, and container handling—appears proportional to the described functionality. While the plan references several operational commands (build/restart) typical of deployment steps, these are not executed by the agent in normal operation according to the description. Overall, the risk posture is low-to-moderate and consistent with a developer tooling enhancement.