agent-export

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose matches migration, but it asks the agent to export highly sensitive internal state—including persona/system-prompt-derived content and arbitrary files—and upload it to an unverified fly.dev relay. The main risk is data exfiltration and hidden-instruction leakage, not malware or installer abuse.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fagent-export%2F@68eddee314973c70ec13d441314f2aed56b0374a