expedite

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow and most capabilities align with the stated expedite purpose, but the Loom integration is the main problem: it relies on a personal GitHub MCP server and forwards a live browser session cookie to third-party code. That makes install trust and credential handling disproportionate to the skill’s otherwise legitimate project-management role. Without the third-party Loom bridge, this would look mostly benign.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:48 PM
Package URL
pkg:socket/skills-sh/readwiseio%2Freadwise-skills%2Fexpedite%2F@547c8f60ebb214ee8c6e4617052b5989fca07d87