second-brain

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
workflows/capture.md

The code fragment describes a straightforward, non-malicious capture flow that writes raw user input to a daily inbox file in a vault with timestamps and a simple confirmation. Primary security considerations are validating vaultPath, sanitizing/encoding user input to prevent markdown issues, and safeguarding vaultPath exposure in logs. Overall risk remains moderate due to local data retention and potential path manipulation if vaultPath handling is not strict.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:39 PM
Package URL
pkg:socket/skills-sh/sean-esk%2Fsecond-brain-gtd%2Fsecond-brain%2F@75be07bb3adc3068ebd8368174df4685807d4527