daily-recap
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated recap purpose mostly matches the local file reads and chat delivery, but the required third-party nano-banana-pro dependency materially changes the trust model. The main risk is transitive installation plus credential forwarding into community-hosted skill code, not the recap logic itself.
Confidence: 84%Severity: 74%
Audit Metadata