session-debrief

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its stated purpose: it analyzes local Claude session history for the current project and summarizes it. The main risks are proportional but non-trivial: it accesses sensitive session logs, relies on a local script outside the skill file, likely forwards session content to MiniMax using an API key stored in a local secrets file, and includes self-modifying instructions to edit the skill itself after execution. Those behaviors make it higher risk than a simple documentation skill, but they are still plausibly related to session debriefing rather than clearly malicious. Overall classification: SUSPICIOUS due to sensitive data access, implied third-party LLM data flow, and self-evolution behavior.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:53 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fsession-debrief%2F@a57cd86d59fdaa3dea48d82719eb3965d7eb48b0