research-archival

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code describes a coherent, admin-oriented workflow for archiving AI research and managing GitHub issues with identity preflight. The footprint aligns with its stated purpose, but it introduces notable security and supply-chain risks: credentials are read from environment/files and used in API calls; multiple external tools and remote commands are invoked; heavy reliance on shell scripting with potential logs exposure; and reliance on internal/private endpoints (ZeroTier, internal IPs) that may be misconfigured or vulnerable if the environment is compromised. While not inherently malicious, the pattern is high-risk for credential exposure, remote control, and potential data leakage if the environment is not tightly controlled. Treat as suspicious enough to warrant strict access controls, secrets management, and auditing of all external interactions and identity checks.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fresearch-archival%2F@2b47978901d0dbf3c6128dc0cefbf59ec6455851