request-analyzer

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The request-analyzer is an orchestration component intended to improve user outcomes by automatically scoring requests and activating specialized skills. The file itself does not contain executable malware, network calls, or hard-coded secrets. The primary security concerns are architectural and operational: broad automatic activation for all requests plus filesystem-read capabilities create a concentration of privilege that can lead to privacy violations or indirect data exfiltration via downstream skills. Recommend limiting automatic activation (opt-in or configurable), scoping file reads, implementing redaction/consent checks prior to forwarding context or attachments, and adding audit/logging for activations. With these mitigations the coordinator can provide value while reducing risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:11 PM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoskills%2Frequest-analyzer%2F@998b60ab7e72762e9ec172722bef0fc5cc372d27