Get Notes Auto Sync

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's stated purpose (syncing and transcribing Get Notes content to a local Markdown store and providing a local dashboard) is coherent with the described capabilities. There are no direct indicators of embedded malware or explicit credential-exfiltration behavior in the provided description. However, the install-and-execute pattern (npm + Playwright browser binary downloads), persistent authentication tokens via automated browser login, and an exposed local dashboard create moderate supply-chain and operational risks. Key mitigations: review the actual scripts for where and how tokens are stored and sent, ensure the dashboard binds to localhost and requires authentication, pin dependency versions, and audit any post-install scripts or network destinations used during install. Overall: no confirmed malware, but moderate security risk due to supply-chain download patterns and persistent credential/storage considerations.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/skychentian%2FGET-biji%2Fget-notes-auto-sync%2F@b600a727ddceb961585c1d7dbaa25916c64ef486