substrate

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill appears coherently aligned with its stated purpose of intra-agent mail management and plan review. Data flows are largely local (inboxes, identity state, plan files) with a local Web UI, which is typical for a agent coordination feature. The only notable behavioral concern is the Stop hook creating a persistent background loop to keep the agent alive, which could mask hidden activity if misused; however, within the documented purpose it serves a planed persistent-work pattern. Overall, the footprint is benign and proportionate to its stated mail/identity/plan-review role, with no evident credential harvesting, external exfiltration, or third-party dependency loading.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:22 AM
Package URL
pkg:socket/skills-sh/roasbeef%2Fclaude-files%2Fsubstrate%2F@faaf486358c1ccbe60dac0eaed273de73124e49c