research-archival

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core GitHub archival purpose is coherent, and GitHub token use goes to official GitHub endpoints, but the skill’s footprint is broader than necessary: it reads local secret-token files, routes scraped content through third-party/private services, and uses SSH to administer remote Firecrawl infrastructure. Those behaviors look operationally motivated rather than overtly malicious, yet they create medium security risk and data-exposure concerns.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 17, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fresearch-archival%2F@389f64398bcd538c56fa63c9555860b2e1b5a5a6